Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Critical “ClawJacked” Flaw Exposes OpenClaw AI Platforms

Critical “ClawJacked” Flaw Exposes OpenClaw AI Platforms

by Tekmono Editorial Team
02/03/2026
in News
Share on FacebookShare on Twitter

A critical vulnerability dubbed “ClawJacked” has been discovered, allowing malicious websites to hijack OpenClaw agents and steal data, posing a significant threat to enterprises and developers relying on OpenClaw for autonomous messaging and task automation.

The flaw exposed self-hosted AI platforms to full workstation compromise. According to Oasis Security, the OpenClaw gateway service binds to localhost by default and exposes a WebSocket interface, making it vulnerable to exploitation.

Because browser cross-origin policies do not block WebSocket connections to localhost, a malicious site can open a silent connection to the local gateway. Oasis noted that the gateway exempts the loopback address from rate limiting, allowing brute-force attempts at hundreds of guesses per second without throttling or logs.

Related Reads

Trump Orders Immediate Halt to Anthropic AI Use

Claude AI Suffers Partial Service Disruption on March 2

Claude Chatbot Overtakes ChatGPT in US App Store

Motorola Unveils Razr Fold with Cutting-Edge Features

“In our lab testing, we achieved a sustained rate of hundreds of password guesses per second from browser JavaScript alone,” the researchers said, highlighting the severity of the vulnerability.

Once the correct password is guessed, the attacker registers as a trusted device and gains admin permissions. This enables credential dumping, node enumeration, log reading, and arbitrary shell command execution, giving attackers comprehensive control over the compromised system.

Oasis reported the issue to OpenClaw, and the vendor released a fix in version 2026.2.26 on February 26. The update sealed the WebSocket checks and re-applied rate limits to loopback connections, addressing the vulnerability.

Organizations running OpenClaw are advised to update to version 2026.2.26 or later immediately to prevent hijacking. OpenClaw is a self-hosted AI platform that lets agents autonomously send messages, execute commands, and manage tasks across multiple services. Its popularity has surged among developers seeking on-premise AI capabilities.

ShareTweet

You Might Be Interested

Trump Orders Immediate Halt to Anthropic AI Use
News

Trump Orders Immediate Halt to Anthropic AI Use

02/03/2026
Claude AI Suffers Partial Service Disruption on March 2
News

Claude AI Suffers Partial Service Disruption on March 2

02/03/2026
Claude Chatbot Overtakes ChatGPT in US App Store
News

Claude Chatbot Overtakes ChatGPT in US App Store

02/03/2026
Motorola Unveils Razr Fold with Cutting-Edge Features
News

Motorola Unveils Razr Fold with Cutting-Edge Features

02/03/2026
Please login to join discussion

Recent Posts

  • Trump Orders Immediate Halt to Anthropic AI Use
  • Claude AI Suffers Partial Service Disruption on March 2
  • Claude Chatbot Overtakes ChatGPT in US App Store
  • Motorola Unveils Razr Fold with Cutting-Edge Features
  • Grok AI Correctly Predicts US-Israel Strikes on Iran

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals