Skip to content
OpenClaw WebSocket Vulnerability Confirmed as Zero-Day by 360 Security Team

OpenClaw WebSocket Vulnerability Confirmed as Zero-Day by 360 Security Team

First seen 22 Mar 2026, 11:14 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 22, 2026 at 22:28 UTC
  • OpenClaw's WebSocket vulnerability is a confirmed zero-day exploit.
  • Attackers can bypass authentication and control the smart agent gateway.
  • 360 Security has reported the vulnerability to CNVD for risk mitigation.

On March 22, 2026, Peter, the founder of OpenClaw, confirmed that the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability was exclusively discovered by the 360 Security Cloud team. This vulnerability is classified as a zero-day, allowing attackers to bypass authentication via WebSocket, potentially gaining control of the smart agent gateway. The exploitation of this vulnerability could lead to resource exhaustion or a complete system crash. The 360 team has reported this high-risk vulnerability to the National Information Security Vulnerability Sharing Platform (CNVD) to mitigate the risk across the network. As of now, there are no specific CVEs assigned to this vulnerability, and no patches have been released yet. The full impact scope remains to be assessed as the situation develops.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 172d ago How this analysis works

Timeline

2026-03-22
OpenClaw founder confirms vulnerability discovered by 360 Security.
2026-03-22
360 Security reports vulnerability to CNVD.

More articles in this cluster (2)

Following this threat?

Track Qihoo 360 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed