Skip to content
OpenClaw Founder Confirms 360's Exclusive Discovery of the Vulnerability

OpenClaw Founder Confirms 360's Exclusive Discovery of the Vulnerability

Techflowpost March 22, 2026

TechFlow News: On March 22, according to JINSHI Data, the Qihoo 360 Cloud Security Team received an official email from Peter, founder of OpenClaw. In his , Peter officially confirmed the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability, which was exclusively discovered by the Qihoo 360 team. Qihoo 360 has already reported this critical vulnerability to the China National Vulnerability Database (CNVD) to help cut off the risk source across the network as soon as possible. This confirmed WebSocket unauthenticated upgrade vulnerability is a zero-day (0Day) vulnerability; attackers can exploit it to silently bypass authentication via WebSocket and gain control over the agent gateway, potentially leading to resource exhaustion or complete system collapse.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Platforms (1)