ClawJack Allows Malicous Sites to Control Local OpenClaw AI Agents - IT Security News
2026-03-01
IT Security News - cybersecurity, infosecurity news

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A critical vulnerability in the OpenClaw AI agent framework, dubbed ClawJacked, allowed malicious websites to hijack locally running AI agents via WebSocket connections. Exploited in the wild, this flaw enabled attackers to gain unauthorized control, access sensitive data, and distribute malware, impacting developers and enterprises globally. The issue has since been patched.[AI generated]