Three high-severity vulnerabilities in OpenClaw, the open-source AI coding and personal assistant, can be chained via WhatsApp to steal credentials, escalate privileges and ultimately achieve remote code execution (RCE) on the host. Security researcher Chinmohan Nayak reported the issues, which affect versions up to 2026.6.1 and are said to be fixed in 2026.6.6. An attacker merely needs to send a malicious WhatsApp message to abuse the AI agent's workflow and run code on the host side. All three carry CVSS scores of 8.4 to 8.8, classifying them as high severity. (report details)
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.