Your personal OpenClaw agent may also be taking orders from malicious websites

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Researchers at Oasis Security disclosed a critical vulnerability (CVE-2026-25253, dubbed ClawJacked) in OpenClaw, a locally running AI agent. The flaw exploits the browser's ability to open WebSocket connections to localhost services, bypassing cross-origin protections. A malicious website can silently connect to the OpenClaw

4m read time From csoonline.com
Post cover image

Sort: