A critical vulnerability in OpenClaw, a rapidly adopted open source AI agent tool, allowed malicious websites to hijack a developer's local AI agent via WebSocket connections to localhost without any user interaction. The flaw exploited OpenClaw's implicit trust of localhost connections and lack of brute-force protections on

5m read time From darkreading.com
Post cover image
Table of contents
High Severity VulnerabilityA Growing List of Security IssuesThe Need for a New Approach

Sort: