Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Critical “ClawJacked” Flaw Exposes OpenClaw AI Platforms

Critical “ClawJacked” Flaw Exposes OpenClaw AI Platforms

by Tekmono Editorial Team
02/03/2026
in News
Share on FacebookShare on Twitter

A critical vulnerability dubbed “ClawJacked” has been discovered, allowing malicious websites to hijack OpenClaw agents and steal data, posing a significant threat to enterprises and developers relying on OpenClaw for autonomous messaging and task automation.

The flaw exposed self-hosted AI platforms to full workstation compromise. According to Oasis Security, the OpenClaw gateway service binds to localhost by default and exposes a WebSocket interface, making it vulnerable to exploitation.

Because browser cross-origin policies do not block WebSocket connections to localhost, a malicious site can open a silent connection to the local gateway. Oasis noted that the gateway exempts the loopback address from rate limiting, allowing brute-force attempts at hundreds of guesses per second without throttling or logs.

Related Reads

OpenAI Wins Pentagon Deal for AI Services

Qualcomm Unveils X105 5G Modem for AI Era

X Lifts Ban on Crypto Paid Promotions

Huawei Launches U6GHz Products for 5G-Advanced Networks

“In our lab testing, we achieved a sustained rate of hundreds of password guesses per second from browser JavaScript alone,” the researchers said, highlighting the severity of the vulnerability.

Once the correct password is guessed, the attacker registers as a trusted device and gains admin permissions. This enables credential dumping, node enumeration, log reading, and arbitrary shell command execution, giving attackers comprehensive control over the compromised system.

Oasis reported the issue to OpenClaw, and the vendor released a fix in version 2026.2.26 on February 26. The update sealed the WebSocket checks and re-applied rate limits to loopback connections, addressing the vulnerability.

Organizations running OpenClaw are advised to update to version 2026.2.26 or later immediately to prevent hijacking. OpenClaw is a self-hosted AI platform that lets agents autonomously send messages, execute commands, and manage tasks across multiple services. Its popularity has surged among developers seeking on-premise AI capabilities.

ShareTweet

You Might Be Interested

OpenAI Wins Pentagon Deal for AI Services
News

OpenAI Wins Pentagon Deal for AI Services

02/03/2026
Qualcomm Unveils X105 5G Modem for AI Era
News

Qualcomm Unveils X105 5G Modem for AI Era

02/03/2026
X Lifts Ban on Crypto Paid Promotions
News

X Lifts Ban on Crypto Paid Promotions

02/03/2026
Huawei Launches U6GHz Products for 5G-Advanced Networks
News

Huawei Launches U6GHz Products for 5G-Advanced Networks

02/03/2026
Please login to join discussion

Recent Posts

  • OpenAI Wins Pentagon Deal for AI Services
  • Qualcomm Unveils X105 5G Modem for AI Era
  • X Lifts Ban on Crypto Paid Promotions
  • Huawei Launches U6GHz Products for 5G-Advanced Networks
  • Users Profit $1 Million on Iran Strike Bets

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals