59m ago
Certik’s March 31 Study Flags Openclaw Flaw CVE-2026-25253 Enabling Admin Takeover
A March 31 report says Openclaw’s security boundaries are breaking down as the AI framework is increasingly deployed on internet-facing servers. It cites CVE-2026-25253 as a critical issue that can lead to full administrative control after a user clicks a single malicious link, and notes 135,000+ exposed instances across 82 countries. The study also describes malware-laced “skills” and prompt-injection paths that could enable data theft or unauthorized actions, while urging sandboxed use and updates to version 2026.1.29 or later.