The OpenClaw AI bot farm is plagued by critical security flaws, including a one-click remote code execution vulnerability and two command injection vulnerabilities. These issues are exacerbated by a repository of 341 malicious extensions, an exposed database, and prevalent prompt injection attacks, leading to a wave of malware, data exposure, and significant financial costs for users.
Why This Matters
The evidence matters to defenders using the affected technology because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether OpenClaw is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected