AI Security · Web App Attack

OpenClaw Flaw Lets Websites Hijack Local AI Agents

A high-severity 'ClawJacked' flaw in OpenClaw let malicious websites open WebSocket connections to the local gateway and brute-force its management password.

5 sources · Mar 6

Timeline

Sources

Part of the PlainSec briefing for 2026-03-02

Every edition of this story: OpenClaw Flaw Lets Websites Hijack Local AI Agents

More from today