Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes—this was a real, reported vulnerability chain. In February 2026, Oasis Security disclosed “ClawJacked,” an attack that allegedly allowed a malicious or compromised website to take authenticated control of a locally running OpenClaw gateway when a user simply visited the page. The attack did not require a malicious plugin, skill, browser extension, or approval beyond opening the website, according to the researchers.

The risk depended on how OpenClaw was configured. An agent with no sensitive integrations has a limited blast radius; one with access to files, email, messaging accounts, shell commands, developer credentials, or paired devices could expose data or perform actions on the user’s behalf.

What OpenClaw does—and why its permissions matter

OpenClaw is local-first infrastructure for running an AI agent that can interact with services and tools on behalf of its operator. Depending on its configuration, an agent may read files, use a browser, send messages, access email, work with repositories, call APIs, or execute commands.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That does not mean every OpenClaw installation is automatically a remote-code-execution service. The practical security impact comes from the capabilities and credentials attached to the agent. A read-only agent running in an isolated environment is very different from an agent operating on a personal workstation with access to SSH keys, cloud accounts, production systems, and private communications.

#1 Best Overall
Kensington Combination Laptop Lock for Standard Security Slot, Resettable (K60213WW), Black
  • 5-Foot (1.5m) Carbon Steel Cable - Resists cutting attempts and provides ample length for easily anchoring your laptop to desks, tables, and other attachment points. Incorporates anti-shearing plastic sleeve to protect surfaces
  • Slim Lock Head - Designed to support thin laptops using standard lock slots, lock secures while allowing your device to lie flat and stable
  • Resettable 4-Wheel Number Code - Set or reset your personal number code from 10,000 possible combinations
  • Pivoting Head and Rotating Anchor - The lock tip rotates 360º and the cable rotates up to 90º—allowing access to the ports near the lock slot on most devices and providing a convenient locking and unlocking experience
  • One-Handed Attachment - Convenient slider allows for quick and easy attachment to the laptop with one hand

OpenClaw’s security guidance describes the project as intended for trusted operators, not as a hostile multi-tenant boundary where mutually distrustful users share one gateway.

What was ClawJacked?

ClawJacked is the name used for the compound attack chain disclosed by Oasis Security. Oasis publicly announced its findings on February 26, 2026, while a Cloud Security Alliance research note dates the disclosure to February 25. Those dates can reflect different points in coordinated disclosure and public release.

According to Oasis, the attack targeted the core OpenClaw gateway running locally on the victim’s computer. It did not depend on installing an unsafe third-party skill or plugin. The website itself acted as the initial attack vehicle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the reported attack worked

The disclosed chain combined several weaknesses or design choices:

  1. The victim ran a vulnerable OpenClaw gateway reachable through a local interface.
  2. The victim visited a malicious or compromised website.
  3. JavaScript on that page attempted to establish a WebSocket connection to the local gateway.
  4. The page tried password guesses against the service.
  5. According to Oasis, loopback traffic was exempt from the gateway’s effective password-rate limiting.
  6. After authentication, the attacker registered a device.
  7. Local device pairing was reportedly approved automatically.
  8. The attacker then used the authenticated connection to issue commands and invoke capabilities available to the agent.

The simplified path was:

Malicious website → browser WebSocket → local gateway → password guessing → trusted pairing → agent tools

Oasis said its proof of concept could interact with the agent without an obvious indication to the user. The exact consequences, however, depended on the agent’s enabled tools, credentials, host permissions, approval settings, sandboxing, and paired devices.

Rank #2
Sale
Kensington Combination Cable T-Bar Standard Lock Slot for Laptops, Resettable 4 digit password with 6 Foot Cable, K64673AM
  • Computer lock for HP, Lenovo, Acer, Asus and other brands; not compatible with Dell or Alienware (see part # K68008WW)
  • Resettable 4-wheel Number code with 10, 000 possible combinations. Push-button design for one-handed engagement to easily attach lock
  • 6’ long carbon steel cable is cut-resistant and anchors to desks, tables, or any fixed structure
  • Attaches to laptops, desktops, TVs, monitors, hard drives, docking stations, projectors or any other device featuring a Kensington standard size security slot
  • Independently verified and tested for industry-leading standards in torque/pull, foreign implements, lock lifecycle, corrosion, key strength and other environmental condition

Why the browser’s same-origin policy did not automatically stop it

The browser’s same-origin policy is important, but it is not a universal barrier against contacting local services. It mainly restricts how a page reads or interacts with resources from another origin. It does not automatically prevent every page from attempting to establish a WebSocket connection to a service listening on the user’s machine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A local service must therefore defend itself. It should validate authentication, authorization, origin or host information, rate-limit attempts—including loopback attempts—and require explicit approval for sensitive device registration. The CSA note identifies insufficient origin or host enforcement as part of the broader root-cause pattern.

This does not mean browsers have no protections or that same-origin policy is useless. It means a service exposed to browser networking cannot treat “localhost” as an inaccessible or inherently trusted network boundary.

What an attacker could do after taking control

Oasis and the CSA note describe authenticated control of the local agent. The potential impact would have varied with each installation:

Agent capability Potential consequence
Email access Search, read, or send messages using the connected account.
Messaging integrations Read conversations, search for secrets, or send messages as the user.
Filesystem access Read, alter, or exfiltrate files available to the agent.
Shell or command tools Run commands with the permissions of the agent or paired node.
Git and cloud credentials Access repositories, deployment systems, APIs, or infrastructure.
Paired devices Use capabilities exposed by trusted connected devices.

“Full control” should not be interpreted as guaranteed operating-system compromise in every case. An agent that can execute arbitrary commands on a workstation may make that outcome possible, but an isolated, read-only deployment without valuable credentials has a much smaller blast radius.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did the attack require a plugin, skill, extension, or click?

According to Oasis, no. The reported attack targeted the core gateway and required no malicious OpenClaw plugin, marketplace skill, browser extension, or additional user interaction beyond visiting the attacker-controlled page.

Rank #3
Sale
Kensington Combination Laptop Lock for Nano Size Security Slot, Resettable 4-Digit Combination Lock (K60214WW)
  • 5-Foot (1.5m) Carbon Steel Cable - Resists cutting attempts and provides ample length for easily anchoring your laptop to desks, tables, and other attachment points. Incorporates anti-shearing plastic sleeve to protect surfaces
  • Slim Lock Head - Designed to support thin laptops using nano sized lock slots (see images for sizing), lock secures while allowing your device to lie flat and stable
  • Resettable 4-Wheel Number Code - Set or reset your personal number code from 10,000 possible combinations
  • Pivoting Head and Rotating Anchor - The lock tip rotates 360º and the cable rotates up to 90º—allowing access to the ports near the lock slot on most devices and providing a convenient locking and unlocking experience

That distinction matters because it separates ClawJacked from attacks in which a user intentionally installs an untrusted skill or plugin. Here, the alleged problem was that an untrusted website could reach a privileged local control plane and cross its authentication and device-pairing boundaries.

Was ClawJacked a prompt-injection attack?

Not primarily. A prompt injection occurs when untrusted content—such as a webpage, document, or email—tries to manipulate an agent’s instructions. For example, a page might tell an agent to ignore its original task and reveal data.

In the ClawJacked report, the website was more than a source of hostile text. The disclosed chain involved a WebSocket connection, password guessing, authentication, and trusted-device registration. That is a network and authorization problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenClaw’s security policy says prompt injection alone is generally not treated as a vulnerability unless it crosses an authentication, authorization, approval, policy, sandbox, or tool boundary. ClawJacked is significant precisely because Oasis said the chain crossed the gateway’s authentication and pairing boundaries.

Who was potentially affected?

The potentially affected population included users who:

  • Ran a vulnerable OpenClaw version.
  • Had a gateway reachable from their local browser.
  • Used an authentication and pairing configuration susceptible to the reported attack path.
  • Connected valuable tools, credentials, services, or devices to the agent.

This does not mean every OpenClaw user was exploitable. The attack required a particular combination of software behavior, gateway exposure, authentication conditions, and available capabilities. A gateway exposed publicly to the internet is a separate—and generally more serious—deployment risk that should be addressed independently.

Rank #4
Computer Laptop Cable Lock for Laptop Computer Tablet Other Digital Device
  • 【For Devices Without Security Lock holes】There is a lock slot plate lined industrial grade double sided adhesive, bound the plate to the hard surface of the devices, then insert the locking head into the plate and loop the cable around a fixed object.
  • 【For Laptops With Built-in Security Lock holes】Just simply insert the lock head into the slot, and loop the cable around a fixed object.
  • 【UPGRADED 100% ANTI THEFT】The lock head is made of super strong stainless steel and double lever lock, thicker and firmer. One key lever push button with 360°rotating, design for one hand operation. 5mm diameter cut-resistant wire braided cable is 30% thicker than normal. Extra length of 6.23ft allows easy movement of device.
  • 【Code Combination】The computer locks utilizes a 4 digit security code. This customizable combination allows you to have over 10,000 different and unique combination. no lost keys!
  • 【PACKAGE INCLUDED】1*Laptop Combination Lock, 1*Double Sided Adhesive Lock Slot Plate, 1*Manual, 3*Spacer. Please contact us if there is any problem with our product. We promise you a 100% satisfaction resolution. No risk, order now!

What fixed the reported issue?

The CSA research note reports that OpenClaw shipped a fix in version 2026.2.25, within 24 hours of the February 25 disclosure. That is the historical remediation version for this reported chain, not a claim that it is the latest release now.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Users should install the latest version available from the official OpenClaw project, confirm the installed version afterward, and review the project’s current security advisories and release notes. Updating is essential, but it does not prove that credentials were never exposed while a vulnerable instance was running.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What OpenClaw users should do now

1. Update and verify

  • Install the latest available OpenClaw release from the official project.
  • Confirm the installed version using the project’s documented version command or interface.
  • Review security advisories and release notes for later fixes as well as the ClawJacked remediation.

2. Rotate credentials

If the vulnerable agent was connected to sensitive services, rotate credentials rather than assuming a software update is enough. Prioritize:

  • AI-provider API keys.
  • Messaging-platform and collaboration tokens.
  • GitHub, GitLab, cloud, database, and deployment credentials.
  • Browser-session tokens or cookies accessible to the agent.
  • SSH keys and other credentials the agent could read.

Revoke active sessions and OAuth grants where supported.

3. Review pairings and integrations

  • Remove unknown or unexpected paired devices.
  • Re-pair only known devices after patching.
  • Inspect connected services and revoke integrations that are no longer required.
  • Check whether the agent had access to personal and business accounts simultaneously.

4. Audit activity

Look for unexpected activity during the period in which the vulnerable version was installed:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • OpenClaw logs, task history, and agent actions.
  • Shell history and command execution records.
  • File access, modification times, and newly downloaded files.
  • Outbound network connections.
  • Email, Slack, Discord, Telegram, GitHub, and calendar activity.
  • New scheduled jobs, startup items, extensions, or persistence mechanisms.

If compromise is suspected, isolate the host, preserve relevant logs, revoke credentials, inspect for persistence, and involve an incident-response team when corporate or production systems were accessible. Do not merely patch and continue operating normally.

Best Value
Multplx Universal Laptop Security Lock | Compatible with All Laptops inc MacBook | 1.7m Anti-Theft Cable | 4 Digit Combination Lock | Cut Resistant Steel Cable
  • Protect laptops from theft. Designed for laptops with no dedicated lock slot. Alternative to Kensington Locks.
  • Works with Macbooks, Surface, Dell, Lenevo and all other major laptops, tablets and notebooks that have a 3.5mm audio port (headphone / AUX port)
  • Extremely durable cut resistant steel cable to tether to to desks, tables, or any fixed structure
  • 1.7 metre cable length providing both flexibility and convenience in cable management
  • Resettable 4-digit combination lock with 10,000 possible combinations. Easy flick switch to lock and unlock for fast setup.

5. Reduce permissions

  • Disable shell execution unless it is genuinely necessary.
  • Use read-only and narrowly scoped credentials.
  • Separate personal and work accounts.
  • Keep secrets out of environments the agent does not need.
  • Use a separate agent for untrusted web research.

Safer deployment practices

For experimentation, run the agent on a dedicated low-privilege account, disposable virtual machine, or carefully configured container instead of a workstation containing personal and production secrets. Containers can help, but they are not a complete security boundary when they have broad filesystem mounts, powerful capabilities, host networking, or unrestricted secret access.

Organizations should inventory locally running agent runtimes, treat agent credentials as privileged secrets, and use separate gateways, hosts, operating-system accounts, or agents when real isolation is required. OpenClaw’s security guidance recommends dedicated machines, VMs, or containers for shared business setups.

For remote gateways, use explicit identity-aware access controls and avoid exposing administrative services directly to the public internet. Network controls, endpoint monitoring, host validation, origin validation, strong authentication, explicit authorization, sandboxing, and human approval gates are complementary defenses—not substitutes for one another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Localhost is not a security boundary by itself

The main architectural lesson extends beyond OpenClaw. A service listening only on a loopback address can still be reachable through programs that the user runs, including a web browser. If that service controls an AI agent with powerful tools, it needs the same disciplined security design expected of any privileged control plane:

  • Strong authentication resistant to guessing.
  • Rate limiting that applies equally to local and non-local attempts.
  • Strict origin and host validation where browser access is possible.
  • Explicit authorization for each sensitive operation.
  • Visible approval and audit events for device pairing.
  • Least-privilege tools and credentials.
  • Isolation from the user’s most sensitive systems.

Related OpenClaw vulnerabilities are not the same issue

OpenClaw continued to receive security fixes after the ClawJacked disclosure. Two later records concern browser-control SSRF issues, not the local WebSocket authentication-and-pairing chain:

  • CVE-2026-43527 affected versions before 2026.4.14 and involved browser navigation to private-network resources.
  • CVE-2026-53812 affected versions before 2026.5.18 and involved action-triggered redirects and access to private-network content.

These records should not be merged into the ClawJacked narrative. They do, however, reinforce the need to keep the project updated and to review security advisories rather than treating one patched version as permanent protection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.