OpenClaw WebSocket Vulnerability Confirmed as Zero-Day by 360 Security Team

OpenClaw WebSocket Vulnerability Confirmed as Zero-Day by 360 Security Team

First seen 22 Mar 2026, 11:14 UTC TechflowpostPanewslab 93% similarity 63.9

Article Content

Browse articles
ThreatCluster

On March 22, 2026, Peter, the founder of OpenClaw, confirmed that the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability was exclusively discovered by the 360 Security Cloud team. This vulnerability is classified as a zero-day, allowing attackers to bypass authentication via WebSocket, potentially gaining control of the smart agent gateway. The exploitation of this vulnerability could lead to resource exhaustion or a complete system crash. The 360 team has reported this high-risk vulnerability to the National Information Security Vulnerability Sharing Platform (CNVD) to mitigate the risk across the network. As of now, there are no specific CVEs assigned to this vulnerability, and no patches have been released yet. The full impact scope remains to be assessed as the situation develops.

Key Points: • OpenClaw's WebSocket vulnerability is a confirmed zero-day exploit. • Attackers can bypass authentication and control the smart agent gateway. • 360 Security has reported the vulnerability to CNVD for risk mitigation.

ThreatCluster AI

Timeline

2026-03-22
OpenClaw founder confirms vulnerability discovered by 360 Security.
2026-03-22
360 Security reports vulnerability to CNVD.

Community

Browse all →

Tracked Entities in This Story