Attackers Exploit OpenClaw Agent Vulnerabilities to Disable Safety Controls

A specific attack chain against OpenClaw's AI agents allowed arbitrary command execution — arriving the same week the framework shipped a security-hardened update.

OpenClaw, the increasingly popular open-source agent framework, suffered a confirmed exploitation this week in which attackers disabled safety controls and executed arbitrary commands through its AI agents, as @aviatrixtrc reported. The timing is uncomfortable: the attack surfaced in the same window that OpenClaw shipped version 2026.6.5, which @marcopapa99 described as featuring "parallel web search + hardened security."

Unlock the full briefing

Get every story in today's briefing, the full archive, and the daily AI intelligence brief.

All stories today

Full archive

Daily brief

Cancel anytime. Payments powered by Stripe.