1 of 1
Story summary
- ClawJacked is a critical OpenClaw AI vulnerability that lets malicious websites hijack local instances and steal data, discovered by Oasis Security.
- The flaw enables a localhost authentication bypass and may allow brute-forcing passwords without alerts.
- OpenClaw patched the vulnerability in version 2026.2.26, released within 24 hours of disclosure.
- Users should update immediately and audit systems, as the attack can lead to full workstation compromise.
