Openclaw Security Breach Exposes Critical Vulnerabilities
- Openclaw, an open-source AI platform, has over 300,000 GitHub stars but is plagued by security issues.
- The framework has accumulated more than 100 CVEs and 280 security advisories within four months.
- Global scans show over 135,000 internet-exposed Openclaw instances across 82 countries, many with authentication disabled by default.
- Critical vulnerability CVE-2026-25253 allows attackers to gain full administrative control through malicious links.
- Malware-infected extensions in the platform’s repository can steal passwords and cryptocurrency wallets.
Openclaw’s rapid growth has led to significant security vulnerabilities due to its deployment on internet-facing servers rather than trusted local environments. The platform’s architectural flaws expose user data to high-risk threats.
Users are advised to run Openclaw in sandboxed environments and update to version 2026.1.29 or later for enhanced security against remote code execution flaws.(Source)