360 Smart Agent discovers critical OpenClaw vulnerability, potentially affecting 170,000 instances worldwide

robot
Abstract generation in progress

Mars Finance and Economics news, March 31. Recently, 360 Digital Security Group learned that its independently developed 360 Multi-Agent Collaborative Vulnerability Mining System has discovered a high-severity vulnerability on the OpenClaw platform—a MEDIA protocol prompt injection that bypasses tool permissions to leak local files. The vulnerability has been officially confirmed by the National Information Security Vulnerability Database (CNNVD). The affected scope covers more than 50 countries and regions worldwide, and more than 170,000 OpenClaw instances that are publicly accessible face security risks. According to the introduction, the core risk of this vulnerability is that the MEDIA protocol runs in the post-processing layer after output, allowing it to completely bypass the platform’s tool policy controls. Even if the Agent disables all tool calls, an attacker can still launch an attack using only the permissions of basic members in group chats, directly stealing sensitive information from the server and very easily triggering subsequent network attacks. (Guo Shi Direct Line)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin