Four Chained OpenClaw Flaws Let Attackers Escape the Agent Sandbox and Seize Full Server Control
Cyera disclosed four chained vulnerabilities in OpenClaw, the "Claw Chain," that escalate from a sandboxed foothold to system-level takeover, stealing credentials, impersonating the owner, and planting a persistent backdoor. The most severe flaw scores CVSS 9.6; roughly 245,000 servers were reachable from the public internet.
Theft of credentials and API keys from the agent environment, owner-level hijacking of the gateway, and persistent backdoors that survive reboots and patching, requiring affected hosts to be rebuilt from clean images with full credential rotation.