A severe, high-level security flaw has been identified in the OpenClaw Gateway. If exploited, attackers can gain full admin control over your Agent.
🔹 The Attack Vector: Simply visiting a malicious website allows hackers to use background JavaScript to brute-force your local WebSocket gateway password hundreds of times per second.
🔹 Immediate Action Required: All users must upgrade to version 2026.2.25 or higher immediately.
🔹 Extra Precaution: Make sure to audit and revoke any unnecessary API keys, credentials, or node access previously granted.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
🚨 Critical Security Alert: OpenClaw Gateway Vulnerability! 🛡️
A severe, high-level security flaw has been identified in the OpenClaw Gateway. If exploited, attackers can gain full admin control over your Agent.
🔹 The Attack Vector: Simply visiting a malicious website allows hackers to use background JavaScript to brute-force your local WebSocket gateway password hundreds of times per second.
🔹 Immediate Action Required: All users must upgrade to version 2026.2.25 or higher immediately.
🔹 Extra Precaution: Make sure to audit and revoke any unnecessary API keys, credentials, or node access previously granted.