'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
New vulnerabilities, dubbed 'Claw Chain,' have been discovered in the OpenClaw open-source AI agent framework, posing a significant risk to deployments. These four flaws – CVE-2026-44112, CVE-2026-44115, CVE-2026-44118, and CVE-2026-44113 – allow attackers to steal credentials, escalate privileges, and establish persistent backdoors. The vulnerabilities stem from time-of-check/time-of-use race conditions and logic flaws, and their combined effect creates a complex attack chain that is difficult to detect, particularly given the framework's integration with sensitive systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
