OpenClaw Founder Responds Confirming 360 Exclusively Discovered Vulnerability

robot
Abstract generation in progress

Deep Tide TechFlow News, March 22 — According to Jinshi Data, the 360 Security Cloud Team received an official email from OpenClaw founder Peter. In his reply, Peter officially confirmed the exclusive discovery by the 360 team of an unauthenticated upgrade vulnerability in OpenClaw Gateway WebSocket. Currently, 360 has reported this high-risk vulnerability to the National Vulnerability Database (CNVD) to help the entire network quickly cut off the source of risk. This confirmed WebSocket unauthenticated upgrade vulnerability is a zero-day (0Day) vulnerability. Attackers can exploit this flaw to silently bypass permission authentication via WebSocket, gaining control of the agent gateway, which could lead to resource exhaustion or total system crash.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin