Image for Article: ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

Article Details

Title
Article: ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
Impact Score
5 / 10
AI Summary (Processed Content)

A high-severity vulnerability, dubbed ClawJacked, was discovered in the core OpenClaw gateway. It allowed a malicious website to brute-force the local gateway's password and gain complete, stealthy control over the AI agent without user interaction. OpenClaw patched the flaw within 24 hours, urging users to update immediately. The report highlights broader security concerns for AI agents due to their extensive system access and attack surface. A separate log poisoning vulnerability in OpenClaw, which could enable indirect prompt injections, was also recently patched.

Original URL
https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html
Source Feed
The Hacker News
Published Date
2026-02-28 17:21
Fetched Date
2026-03-04 13:39
Processed Date
2026-03-04 13:58
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content