ended4월 18일· 1 sources

Critical OpenClaw Flaw Allows Unauthenticated Remote Sandbox Access

OpenClaw 중대 취약점, 원격 공격자가 인증 없이 샌드박스 제어 가능

Why it matters

This critical vulnerability (CVSS 9.8) completely bypasses OpenClaw's authentication, enabling remote attackers to gain interactive control over the AI platform's sandboxed browser environment. Proof-of-concept exploits are already publicly available, making immediate patching essential for affected organizations. The flaw directly undermines the security foundation of AI assistant platforms by exposing the sandbox layer designed to isolate AI operations from unauthorized access.

1
Sources
+0
24h
Growth
156d
Active
OpenClawAuthentication BypassSandbox AccessMiddleware MisconfigurationInformation Leakage

Sources

Related Issues