ended4월 18일· 1 sources
Critical OpenClaw Flaw Allows Unauthenticated Remote Sandbox Access
OpenClaw 중대 취약점, 원격 공격자가 인증 없이 샌드박스 제어 가능
Why it matters
This critical vulnerability (CVSS 9.8) completely bypasses OpenClaw's authentication, enabling remote attackers to gain interactive control over the AI platform's sandboxed browser environment. Proof-of-concept exploits are already publicly available, making immediate patching essential for affected organizations. The flaw directly undermines the security foundation of AI assistant platforms by exposing the sandbox layer designed to isolate AI operations from unauthorized access.
1
Sources
+0
24h
—
Growth
156d
Active
OpenClawAuthentication BypassSandbox AccessMiddleware MisconfigurationInformation Leakage