Clawdbot Prompt Injection Vulnerability
Evidence indicates that Clawdbot is affected by prompt injection.
What Happened
Evidence indicates that Clawdbot is affected by prompt injection.
Why This Matters
The evidence matters to defenders using Clawdbot because it may let untrusted content influence connected tools or sensitive workflows.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether Clawdbot is present in your environment and review the affected configuration.
Exposure
Feb 09, 2026 05:30
Feb 09, 2026 05:30
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Feb 09, 2026 05:30BugSkan first recorded this incident.
-
OpenClaw🦞 (ex-Moltbot (ex-Clawdbot)): The AI Butler With Its Claws On The Keys To Your Kingdom - bitsight.com
Feb 09, 2026 05:30bitsight.com · Vulnerability
Sources
bitsight.com · Feb 09, 2026 05:30
OpenClaw, a rapidly adopted AI assistant with broad system access, presents significant security risks due to widespread deployment of internet-exposed instances by users. Threat actors are actively exploiting these misconfigurations, conducting prompt injection attempts and direct attacks via the WebSocket API for authentication bypasses and raw command execution.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.