criticalSecurity flaw UnknownPublish anonymously
OpenClaw AI agent security crisis — 138 CVEs in 63 days, 341 malicious marketplace skills
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
OpenClaw (135K+ GitHub stars) had over 138 CVEs in 63 days. CVE-2026-25253 (CVSS 8.8) enabled one-click RCE. Over 21,000 publicly exposed instances found. 341 malicious skills (~12% of ClawHub marketplace) performed credential theft and lateral movement across connected enterprise SaaS apps.