Back to IntelRead Original Source
Intel Node
New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
lowadvisory2026-06-11T17:46:32+00:00source excerpt
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them.