Sunday, March 1, 2026
HomeTechnologyClawJacked assault let malicious web sites hijack OpenClaw to steal information

ClawJacked assault let malicious web sites hijack OpenClaw to steal information

ClawJacked assault let malicious web sites hijack OpenClaw to steal information

Safety researchers have disclosed a high-severity vulnerability dubbed “ClawJacked” within the standard AI agent OpenClaw that allowed a malicious web site to silently bruteforce entry to a domestically operating occasion and take management over it.

Oasis Safety found the problem and reported it to OpenClaw, with a repair being launched in model 2026.2.26 on February 26.

OpenClaw is a self-hosted AI platform that has lately surged in reputation for enabling AI brokers to autonomously ship messages, execute instructions, and handle duties throughout a number of platforms.

In keeping with Oasis Safety, the vulnerability is attributable to the OpenClaw gateway service binding to localhost by default and exposing a WebSocket interface.

As a result of browser cross-origin insurance policies don’t block WebSocket connections to localhost, a malicious web site visited by an OpenClaw person can use JavaScript to silently open a connection to the native gateway and try authentication with out triggering any warnings.

Whereas OpenClaw contains fee limiting to forestall brute-force assaults, the loopback tackle (127.0.0.1) is exempt by default, so native CLI classes usually are not mistakenly locked out.

The researchers discovered that they may brute-force the OpenClaw administration password at tons of of makes an attempt per second with out failed makes an attempt being throttled or logged. As soon as the proper password is guessed, the attacker can silently register as a trusted gadget, because the gateway routinely approves gadget pairings from localhost with out requiring person affirmation.

“In our lab testing, we achieved a sustained fee of tons of of password guesses per second from browser JavaScript alone,” explains Oasis.

“At that pace, a listing of frequent passwords is exhausted in beneath a second, and a big dictionary would take solely minutes. A human-chosen password does not stand an opportunity.”

With an authenticated session and admin permissions, the attacker can now work together instantly with the AI platform, dumping credentials, itemizing related nodes, stealing credentials, and studying software logs.

Oasis says this might enable an attacker to instruct the agent to go looking messaging histories for delicate info, exfiltrate recordsdata from related units, or execute arbitrary shell instructions on paired nodes, successfully leading to full workstation compromise triggered from a browser tab.

Oasis shared an indication of this assault, displaying the way it might be used to steal delicate information by way of the OpenClaw vulnerability.

Oasis reported the problem to OpenClaw, together with technical particulars and proof-of-concept code, and it was fastened inside 24 hours of disclosure.

The repair tightens WebSocket safety checks and provides further protections to forestall attackers from abusing localhost loopback connections to brute-force logins or hijack classes, even when these connections are configured to be exempt from fee limiting.

Organizations and builders operating OpenClaw ought to replace to model 2026.2.26 or later instantly to forestall their installations from being hijacked.

With OpenClaw’s large reputation, safety researchers have been specializing in figuring out vulnerabilities and assaults concentrating on the platform.

Risk actors have been seen abusing the “ClawHub” OpenClaw abilities repository to advertise malicious abilities that deploy infostealing malware or trick customers into operating malicious instructions on their units.

Malware is getting smarter. The Crimson Report 2026 reveals how new threats use math to detect sandboxes and conceal in plain sight.

Obtain our evaluation of 1.1 million malicious samples to uncover the highest 10 strategies and see in case your safety stack is blinded.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments