
High-Severity Vulnerabilities in OpenClaw AI Assistant Patched After Disclosure
A security researcher disclosed details of three now-patched high-severity vulnerabilities in OpenClaw, a personal AI assistant, which could enable credential theft, privilege escalation, and arbitrary code execution on the host system. One of the flaws, tracked as GHSA-hjr6-g723-hmfm, carries a CVSS score of 8.8, though the other two vulnerabilities were not fully detailed in the available content. The attack chain leverages these OpenClaw flaws to compromise systems, with exploitation potential extending from WhatsApp interactions to host-level access. No specific dates for disclosure or patching were provided, nor were the full CVE identifiers or additional technical specifics of the remaining vulnerabilities. The impacts include unauthorized system control and data exfiltration.