Security researchers have discovered six vulnerabilities (ranging from moderate to critical severity) affecting the open-source AI agent framework, OpenClaw, which is known as "social media for AI agents."

The vulnerabilities were discovered by Endor Labs when its researchers ran the platform through a static application security testing (SAST) engine that uses AI. The engine is designed to observe how data actually moves through agentic AI software.
See also: Chinese hackers exploited vulnerability in Dell RecoverPoint
OpenClaw vulnerabilities
The bugs fall into several categories of vulnerabilities, including server-side request forgery (SSRF), missing webhook authentication, authentication bypasses, and path traversal. All of these affect the complex agentic system that combines large language models (LLMs) with tool execution and external integrations.
The researchers also published proof-of-concept exploits for each of the flaws, confirming their exploitability. OpenClaw has published updates and advisories for the issues.
Endor Labs analyzed the six OpenClaw vulnerabilities based on their vulnerability type and severity (rather than CVE identifiers).
See also: Vulnerabilities in PDF platforms allow data theft
Several of the issues are SSRF bugs affecting various tools, including a gateway component (CVSS 7.6) that accepts user-supplied URLs to create outbound WebSocket connections. The other two included an SSRF in Urbit Authentication (CVSS 6.5) and an Image Tool SSRF (CVSS 7.6). These SSRF paths could allow access to internal services or cloud metadata endpoints, depending on the deployment.

Access control failures represented another set of findings. A “ Telnyx ” webhook handler designed to receive external events lacked proper webhook verification (CVSS 7.5), allowing forged requests from untrusted sources. Separately, an authentication bypass (CVSS 6.5) allowed unauthenticated users to call a protected “ Twilio ” webhook functionality without valid credentials.
Finally, a path traversal (CVSS not assigned) was identified in the browser's upload handling, where insufficient sanitization of file paths could allow writes outside of the intended directories.
See also: Microsoft: Bug allows Copilot to summarize confidential emails

“The combination of AI-powered analysis and systematic manual validation provides a practical path to securing AI infrastructure,” the researchers said. “As AI agent frameworks become more prevalent in enterprise environments, security analysis must evolve to address both traditional vulnerabilities and AI-specific attack surfaces.”
Endor Labs said it responsibly disclosed the vulnerabilities to OpenClaw administrators, who then addressed the issues, allowing the researchers to publish technical details. The disclosure did not provide extensive guidance on how to address them, but noted that fixes had been applied to affected components.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
