The "ClawJacked" vulnerability in the OpenClaw AI personal assistant allows malicious websites to silently hijack a user's local AI agent. This exploit abuses the AI agent's inherent trust in localhost WebSocket connections, enabling attackers to bypass authentication and gain full control over the agent with system privileges.
Why This Matters
Publisher reporting describes a security event affecting openclaw. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether openclaw is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected
OpenClawOpenClaw AI personal assistantAI AgentsCan Let MaliciousLatest OpenClaw FlawWebsites Hijack Local