New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
EXPIRED
60.5
2026-06-12T07:00
Score-Aufschlüsselung
100
novelty
35
reach
45
concrete_impact
65
emotional_hook
70
source_quality
55
platform_fit
Zusammenfassung
Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built a test agent on
Skripte (0)
7bed29a5…
Noch kein Skript generiert.
Score 60.5 — unter Schwellwert (65)