INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ClawJacked Vulnerability Exploited via Malicious Links

| 2026-02-27 16:39 HIGH HIGH
Executive Summary AI-generated
The recent discovery of a critical vulnerability in OpenClaw, dubbed ClawJacked, has exposed the potential for malicious actors to hijack AI agents. This flaw, which was identified by researchers at Oasis Security and revealed through WebSockets, allows attackers to gain admin-level permission on affected systems and access sensitive information such as private Slack messages, API keys, and files. The vulnerability is particularly concerning given its rapid success, with the tool exploding in popularity just weeks after being released. Experts warn that this incident should serve as a wake-up call for identity security, highlighting the need to treat AI agents as highly privileged systems.
Technical Mitigations AI-generated
* Verify local connections: Before connecting to a website, verify that the connection is coming from the user's own machine (localhost) and not a malicious link. This can be done by checking if the URL starts with "http://localhost/" or "/api/". If it does, consider using a more secure protocol like HTTPS. * Use secure authentication mechanisms: Ensure that any authentication mechanism used in OpenClaw is secure and properly implemented. Consider using token-based authentication, OAuth, or other secure protocols to prevent unauthorized access. * Limit password guessing attempts: Implement rate limiting on password guessing attempts for users connecting from the same machine. This can be done by checking if a user has already attempted to guess their password within a certain time frame (e.g., 60 seconds). * Implement WebSocket encryption: Use end-to-end encrypted WebSockets when communicating with OpenClaw's API. This will prevent eavesdropping and tampering attacks. * Regularly update dependencies: Regularly update all dependencies, including libraries and frameworks used in OpenClaw, to ensure that any known vulnerabilities are patched before they can be exploited by attackers. Note: These mitigations may not completely eliminate the risk of a successful attack, but they can help reduce it.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-25253CVE-2026-25253
Target & Sectors
Global Scope technologytechnology
Incident Timeline
Febrero 02, 2026
Threat actors used a previously unknown vulnerability in OpenClaw to gain unauthorized access and potentially hijack AI agents controlling websites.
2026-02-27
OpenClaw es una plataforma de agentes abiertos que permite a los usuarios configurar y utilizar sus propios entornos de desarrollo personalizados.
organisation The Oasis Research
organisation ClawJacked
organisation el 30
infrastructure 2026.2.25
organisation ClawJacked Vulnerability
organisation OpenAI’s Sam Altman
organisation Oasis Security
organisation The Silent Hijack Oasis’s
organisation WebSockets
organisation WebSocket
organisation el enlace a esa página
organisation un ataque de secuestro
organisation el servidor de OpenClaw
organisation API
organisation OpenClaw
organisation Hackread.com
organisation Noma Security
organisation Cequence Security
organisation SailPoint
organisation Vulnerabilidad / Inteligencia Artificial
organisation defecto de seguridad de alta gravedad
organisation remota del código
organisation un
organisation El Control UI
organisation el WebSocket
organisation el encargado de
organisation políticas de herramientas
organisation autónomo de inteligencia
organisation funciona desde
organisation los servidores de otra
organisation VPS
organisation cadena de explotación
organisation RCE de un
organisation el encabezado de origen
organisation el servidor
organisation el token robado
organisation aprobaciones de alcances
organisation de un LLM
organisation los usuarios
organisation limitar el radio de explosión
organisation UI Control
organisation el host de la puerta de entrada
organisation El ataque funciona
Tactical Metrics
Metrics
infrastructure
​2026.2.25
Software Version