CNCERT warns OpenClaw of security prompt‑injection risk

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CNCERT posted a WeChat warning that OpenClaw's default security settings are weak and its privileged system access could be exploited by malicious actors to take control of endpoints.
- OpenClaw (formerly Clawdbot and Moltbot) is an open‑source, self‑hosted autonomous AI agent that can execute tasks autonomously, raising security concerns.
- Prompt injection attacks, including indirect prompt injection (IDPI) and cross‑domain prompt injection (XPIA), can trick OpenClaw into leaking sensitive data by embedding malicious instructions in web content it processes.
- OpenAI recently noted in a blog post that prompt‑injection techniques are evolving to incorporate social‑engineering elements beyond simple content manipulation.
- Attack vectors described range from evading AI‑based ad‑review systems and influencing hiring decisions to SEO poisoning and biasing responses by suppressing negative reviews.
Why it matters: Enterprises and users deploying OpenClaw risk data exposure and loss of system control, while attackers gain a new vector to compromise endpoints via indirect prompt injection, raising security concerns for the broader open‑source AI ecosystem and may affect downstream applications.



