ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket Emmie Evans February 28, 2026

ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket

OpenClaw has fixed a high-severity security issue that, if successfully exploited, could have allowed a malicious website to connect to a locally running artificial intelligence (AI) agent and take over control.
“Our vulnerability lives in the core system itself – no plugins, no marketplace, no user-installed extensions – just the bare OpenClaw gateway, running exactly as documented,” Oasis

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top