‘A human-chosen password doesn’t stand a chance’: OpenClaw has another major security flaw – here’s what we know about “ClawJacked”


  • Oasis security researchers find a serious flaw in the OpenClaw AI agent
  • Exploitation allowed malicious websites to brute-force local gateway authentication and gain full control
  • Vulnerability fixed within 24 hours; users are encouraged to upgrade to version 2026.2.25 or later

OpenClaw, the wildly popular open source AI agent platform, was vulnerable to a serious flaw that allowed threat actors to steal sensitive data from target computers with relative ease, experts have warned.

The flaw was discovered by security researchers Oasis and was fixed after responsible disclosure.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top