Cybersecurity researchers at Cyera disclose four vulnerabilities in OpenClaw that can be chained to enable data theft, privilege escalation, and persistence on a compromised system. The issues are collectively referred to as “Claw Chain.” According to the reporting, the flaws affect components of OpenClaw’s managed sandbox environment, including its OpenShell managed sandbox backend and its MCP loopback runtime. Researchers describe how an attacker could use the vulnerabilities together to first establish a foothold and then reach capabilities such as exposing sensitive information, escalating privileges, and planting backdoors that maintain continued control over the affected host. Both outlets characterize the risk as arising from chaining the four flaws rather than any single issue alone. The Next Web also notes that patches are available in OpenClaw, indicating that the vulnerabilities have been addressed. Overall, the disclosures focus on how weaknesses in the agent’s sandbox-related functionality could allow malicious activity that undermines the intended isolation boundaries, with the combined “Claw Chain” workflow supporting sustained, elevated access.
Cyera discloses four OpenClaw vulnerabilities enabling chained data theft and persistence
Cybersecurity researchers at Cyera disclose four vulnerabilities in OpenClaw that can be chained to enable data theft, privilege escalation, and persistence on a compromised system. The issues are col...
- Cyera researchers disclose four vulnerabilities in OpenClaw that can be chained together.
- The vulnerabilities are collectively called “Claw Chain.”
- The chain can enable data theft, privilege escalation, and persistence/backdoor planting.
- The issues affect parts of OpenClaw’s sandbox-related components, including the OpenShell managed sandbox backend and the MCP loopback runtime.
- OpenClaw patches are available to address the reported vulnerabilities.
Cybersecurity researchers at Cyera have disclosed four vulnerabilities in OpenClaw that, when chained together, allow an attacker to steal sensitive data, escalate privileges, and establish persistent control over a compromised host. The flaws, collectively dubbed “Claw Chain,” affect OpenClaw’s OpenShell managed sandbox backend and its MCP loopback runtime. All four have been patched in OpenClaw […] This story continues at The Next Web
3 months agoCybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below -
3 months ago
Google DeepMind launches Gemini Omni 1.1 Flash for developers
Google DeepMind introduces Gemini Omni 1.1 Flash, a new offering aimed at developers building generative AI applications...
Google unveils Fitbit Air Special Edition themed for Pokémon Sleep
Google announces a Fitbit Air Special Edition designed to work with the Pokémon Sleep app. The device is positioned as a...
Google expands Search’s AI Mode with flight price tracking and hotel booking tools
Google is expanding its Search “AI Mode” with new trip-planning features. The update adds flight price tracking and tool...