clawsmith.com/signal/clawjacked-openclaw-vulnerability-localhost-hijack
⚠ IssueUnknownSecurity AdvisoryLive
ClawJacked: any website can silently hijack local OpenClaw agents via WebSocket brute-force
Browser cross-origin policies don't block WebSocket connections to localhost. Any malicious website can brute-force the gateway password at hundreds of attempts/second (rate limiter exempts localhost) and take full agent control. Patched in v2026.2.26 within 24 hours.
Product Idea from this Signal
A network firewall that blocks WebSocket hijack attacks on local OpenClaw agents before malicious sites connect
900 ▲SECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity →
Social Proof 4 sources
Frequently Asked Questions
Virality Score
0
across 9 platforms
Details
Signalissue
EcosystemSecurity Advisory
Sources4
Platforms9
Updated11d ago
Trend→ stable
Top ideas
All ideas →