CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

ClawJacked Flaw in OpenClaw Enables Local AI Agent Hijacking via WebSocket

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A high-severity vulnerability in OpenClaw, codenamed ClawJacked, allows malicious websites to hijack locally running AI agents through WebSocket connections. The flaw exploits missing rate-limiting and auto-approval of trusted devices, enabling attackers to take control of the AI agent. OpenClaw has released a fix in version 2026.2.25, urging users to update immediately and enforce strict governance controls.

Timeline

  1. 28.02.2026 19:21 1 articles · 5h ago

    ClawJacked Flaw in OpenClaw Enables Local AI Agent Hijacking via WebSocket

    A high-severity vulnerability in OpenClaw, codenamed ClawJacked, allows malicious websites to hijack locally running AI agents through WebSocket connections. The flaw exploits missing rate-limiting and auto-approval of trusted devices, enabling attackers to take control of the AI agent. OpenClaw has released a fix in version 2026.2.25, urging users to update immediately and enforce strict governance controls.

    Show sources

Information Snippets