Panewslab
OpenClaw WebSocket Vulnerability Confirmed as Zero-Day by 360 Security Team
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On March 22, 2026, Peter, the founder of OpenClaw, confirmed that the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability was exclusively discovered by the 360 Security Cloud team. This vulnerability is classified as a zero-day, allowing attackers to bypass authentication via WebSocket, potentially gaining control of the smart agent gateway. The exploitation of this vulnerability could lead to resource exhaustion or a complete system crash. The 360 team has reported this high-risk vulnerability to the National Information Security Vulnerability Sharing Platform (CNVD) to mitigate the risk across the network. As of now, there are no specific CVEs assigned to this vulnerability, and no patches have been released yet. The full impact scope remains to be assessed as the situation develops.
Key Points: • OpenClaw's WebSocket vulnerability is a confirmed zero-day exploit. • Attackers can bypass authentication and control the smart agent gateway. • 360 Security has reported the vulnerability to CNVD for risk mitigation.