Affected Systems
OpenClaw self-hosted AI agent platform, all versions. Vulnerability affects input processing mechanisms for vCards, location pins, and potentially other structured data formats.
Exploitation Status
Proof-of-concept demonstrated by Imperva and Varonis security researchers. Active exploitation status unknown. Attack vectors are practical and require minimal sophistication.
Business Impact
Attackers can execute arbitrary code on systems running OpenClaw and exfiltrate sensitive data through prompt injection attacks embedded in common file formats. Organizations using OpenClaw for processing user-supplied content or integrating external data sources face immediate risk. No CVE assigned yet, limiting visibility in vulnerability scanners. CVSS score not published.
Urgency
🟠Within 24 hours
Recommended Actions
- Immediately audit all OpenClaw deployments and identify instances processing untrusted vCards, location data, or user-supplied structured inputs
- Implement strict input validation and sanitization for all data processed by OpenClaw agents, particularly vCard and geolocation formats
- Enable logging for all OpenClaw agent actions and monitor for unexpected code execution, file access, or network connections
- Restrict OpenClaw agent permissions using principle of least privilege and isolate instances in sandboxed environments
- Contact OpenClaw vendor for security patches and subscribe to their security advisories for updates
