Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer

A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a modern laptop on a dark wooden desk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A security researcher found three high-severity flaws in OpenClaw, a personal AI assistant, that together let an attacker take over the user's computer.
  • The most serious bug, tracked as GHSA-hjr6-g723-hmfm, scores 8.8 out of 10 and lets an attacker run operating system commands on the host.
  • The attack chain can be triggered by a single WhatsApp message, with no extra clicking required beyond normal use of the assistant.
  • All three vulnerabilities have been patched; users should update immediately.

A researcher has gone public with details of three security holes in OpenClaw, a personal AI assistant that people install on their own computers to help with everyday tasks. All three are now fixed, but the write-up shows how badly things could've gone for anyone still on an older version.

The short version: an attacker sends a WhatsApp message to the victim and ends up running commands on the victim's laptop. For a desktop app, that's about as bad as it gets. The report was first covered by The Hacker News.

This isn't OpenClaw's first rough month. We reported in June that two research teams showed the assistant would execute attacker instructions smuggled inside contacts, location pins, and other benign-looking inputs.

How did the attack actually work?

Chaining three bugs together is what makes this dangerous, because each one alone is limited.

The headline flaw is GHSA-hjr6-g723-hmfm, scored 8.8 out of 10 on the industry severity scale. It's what engineers call OS command injection: the assistant takes text it receives and, instead of treating it as plain words, hands part of it to the underlying operating system to execute. Feed it the right booby-trapped string and the machine runs whatever the attacker chose.

The other two flaws complete the chain. One lets an attacker pull credentials, specifically stored passwords and login tokens, from the assistant's own storage. The other elevates the attacker's privileges on the machine, so the code they run isn't stuck inside a limited sandbox. Net result: message arrives, passwords lift, commands run as a trusted user.

This is the classic AI-assistant failure mode. These tools are designed to act on natural language. When that language arrives over an outside channel like WhatsApp, the app has to be paranoid about what it does with it. Vulnerable versions of OpenClaw weren't.

Should ordinary users be worried?

If you use OpenClaw, update it now and the risk goes away. The maintainers have shipped patches for all three issues.

If you don't use it, this pattern still deserves attention. Desktop AI assistants sit in a privileged spot on your machine: they read your messages, open files, and some execute shell commands on your behalf. A bug in that plumbing isn't a small bug.

Two practical checks for anyone running an AI assistant on a personal or work laptop: look at what messaging apps and inboxes it's connected to, because anything that can send you a message can in theory send it a payload; and keep the software updated, because AI tooling is moving fast and so are the patches.

One thing the post-mortem will say is that the assistant treated inbound message content as trusted input. That assumption is going to bite a lot of vendors before the year is out.

If your AI assistant can run shell commands, treat every message it reads as untrusted user input, because that's exactly what it is.

© 2026 Threat Vectr