AI Headlines Pro
NewsToolsBoostStartupsResearch

Daily AI briefing

No spam, unsubscribe anytime.

AI Headlines Pro

Your premier source for the latest AI news, breakthroughs, tools, and startups in the fast-evolving world of Artificial Intelligence.

Quick Links

  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • RSS Feed

Categories

  • News
  • Tools
  • Startups
  • Research
  • Saved
  • Boost Your Tool
  • Submit Tool

© 2026 AI Headlines Pro. All rights reserved.

CybersecurityJuly 11, 2026

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

A brief description of the high-severity vulnerabilities is as follows -

T
The Hacker News
~3 min read

Ravie LakshmananJul 10, 2026AI Security / Vulnerability * Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vulnerabilities is as follows -

  • GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller's intended authorization.

  • GHSA-9969-8g9h-rxwm (CVSS score: 8.8) - An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller's intended authorization.

  • GHSA-575v-8hfq-m3mc (CVSS score: 8.4) - A path traversal and link following vulnerability that could allow sandbox bind mounts to bypass parent-directory denylist checks and perform actions that should have been secured with stronger authorization or policy checks.

All three shortcomings have been addressed in OpenClaw version 2026.6.6.

* In a series of advisories released last week, OpenClaw maintainers said "practical impact depends on the operator's configuration and whether lower-trust input can reach that path."

However, security researcher Chinmohan Nayak, who is credited with discovering and reporting the issues, said in a report shared with The Hacker News that they can be used to trigger host code execution from an external message sent via WhatsApp.

* Unlike the Claw Chain vulnerabilities disclosed by Cyera back in May, the newly identified bugs do not require an attacker to establish a prior foothold in order to extract sensitive data, drop a persistent backdoor, obtain arbitrary remote code execution, and facilitate an escape to the host.

"getBlockedReasonForSourcePath() checks if the source path is under a blocked path," the researcher explained about GHSA-575v-8hfq-m3mc. "But [it] never checks the reverse — whether a blocked path is under the source (parent directory bypass)."

* Specifically, the bind mount denylist blocks directories like "/.ssh," "/.aws," and "~/.gnupg,” but allows mounting the parent directory "/home" or "/var," effectively undermining the individual blocks.

"Mount /home into your container, and you can read every user's SSH keys, AWS credentials, and GPG secrets," Nayak said. "Mount /var and you get the Docker socket – which means full host escape from inside the 'sandbox.'"

Besides updating OpenClaw to the latest version, it's advised to enable sandbox mode for all non-main sessions, remove "exec" from the tool allowlist for channel-facing agents, and monitor for git clone commands containing the "ext::" external protocol helper that could be abused to run arbitrary system commands.

"Before upgrading, restrict the affected feature to trusted operators or disable it when it is not needed," OpenClaw said. "As general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

SHARE    

Tweet Share Share Share

SHARE  AI Security, Application Security, Code Execution, Container Security, Messaging Security, Open Source, privilege escalation, Sandbox Escape, Vulnerability

Topics

aiartificial intelligencegooglesecurityhackvulnerabilityagent

Sources

  • https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html

Share this article

Twitter/XLinkedInRedditWhatsApp

Related Articles

CybersecurityJul 14· thehackernews.com

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD Report.html to measure the success of…

The Hacker News·~5 min
aiartificial intelligence
CybersecurityJul 14· thehackernews.com

Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling

Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would check in only at set…

The Hacker News·~5 min
aiartificial intelligence
CybersecurityJul 14· thehackernews.com

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

On the flight home, I picked up a book I had not touched in a few years. Daniel Kahneman's Thinking, Fast and Slow. Kahneman is one of the rare people who genuinely changed how we understand human decisionmaking. He…

The Hacker News·~9 min
aiartificial intelligence

Related AI Tools

ChatGPT

AI-powered conversational assistant by OpenAI

Freemium4.5 ★

Claude

AI assistant by Anthropic with strong reasoning

Freemium4.6 ★

Midjourney

AI image generation from text prompts

Paid4.7 ★
← Back to all news