The OpenClaw ecosystem faces ongoing security vulnerabilities, including a recently patched one-click remote code execution exploit that allowed attackers to hijack AI agents through malicious web pages. The exploit chain leveraged cross-site WebSocket hijacking due to missing origin header validation, enabling attackers to
Sort: