OpenClaw Founder Confirms 360's Exclusive Discovery of the Vulnerability
TechFlow News: On March 22, according to JINSHI Data, the Qihoo 360 Cloud Security Team received an official email from Peter, founder of OpenClaw. In his , Peter officially confirmed the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability, which was exclusively discovered by the Qihoo 360 team. Qihoo 360 has already reported this critical vulnerability to the China National Vulnerability Database (CNVD) to help cut off the risk source across the network as soon as possible. This confirmed WebSocket unauthenticated upgrade vulnerability is a zero-day (0Day) vulnerability; attackers can exploit it to silently bypass authentication via WebSocket and gain control over the agent gateway, potentially leading to resource exhaustion or complete system collapse.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
