Security researcher Chinmohan Nayak has detailed how three now-patched OpenClaw vulnerabilities can be chained together to go from a WhatsApp message to full host code execution. The attack chain exploits command injection, path traversal, and bind mount bypass flaws in the popular open-source AI assistant platform.
OpenClaw is an open-source personal AI assistant that runs locally and integrates with messaging platforms such as WhatsApp, Slack, and Discord. With Sandbox Mode acting as a lightweight container isolation layer, OpenClaw executes user-submitted code and commands while attempting to restrict access to sensitive host resources. But the three vulnerabilities disclosed this week break that isolation in multiple ways.
Vulnerability Details
GHSA-hjr6-g723-hmfm (CVSS 8.8) -- Command Injection in Host Execution
The first flaw is an OS command injection vulnerability in the host execution environment filtering mechanism. OpenClaw maintains an allowlist and denylist of commands that AI agents can execute, but the filtering can be bypassed. An attacker who can send messages to an OpenClaw-powered agent on WhatsApp can craft inputs that slip past the filters and run arbitrary system commands on the host.
GHSA-9969-8g9h-rxwm (CVSS 8.8) -- Incomplete Disallowed Inputs
The second flaw has the same CVSS score of 8.8 and affects the same filtering mechanism from a different angle. The incomplete list of disallowed inputs means certain dangerous patterns are not blocked, allowing attackers to execute or persist actions beyond the caller's intended authorization. Together with the first vulnerability, this gives adversaries multiple vectors to achieve the same goal: arbitrary code execution.
GHSA-575v-8hfq-m3mc (CVSS 8.4) -- Path Traversal via Bind Mount Bypass
The third vulnerability is a path traversal and link following flaw in the sandbox's bind mount denylist. The bind mount system blocks directories like ~/.ssh, ~/.aws, and ~/.gnupg from being mounted inside the container. However, the checking logic only verifies whether the source path is under a blocked path -- it never checks the reverse scenario where a blocked path falls under an allowed parent directory.
As Nayak explained: "getBlockedReasonForSourcePath() checks if the source path is under a blocked path. But it never checks the reverse -- whether a blocked path is under the source."
This means an attacker can mount the parent directory /home or /var instead of the specific blocked subdirectories:
- Mount
/homeinto the container, and the attacker can read every user's SSH keys, AWS credentials, and GPG secrets - Mount
/varand they get the Docker socket -- which means full host escape from inside the sandbox
Impact Assessment
All three vulnerabilities have been addressed in OpenClaw version 2026.6.6. The OpenClaw maintainers acknowledged the risks, noting that "practical impact depends on the operator's configuration and whether lower-trust input can reach that path."
But the real danger comes from chaining them. A WhatsApp message can trigger host code execution without requiring a prior foothold on the system. Unlike vulnerabilities disclosed earlier by Cyera, these bugs do not require the attacker to already have access to the target machine.
What attackers can achieve
- Extract sensitive data (SSH keys, cloud credentials, GPG secrets)
- Drop persistent backdoors
- Obtain arbitrary remote code execution
- Escape the sandbox entirely to the host operating system
Affected Systems
Any OpenClaw instance running a version prior to 2026.6.6 is vulnerable. This includes deployments configured with:
- WhatsApp, Slack, or Discord channels connected to OpenClaw agents
- Sandbox Mode enabled (the vulnerabilities bypass it, so sandboxing does not fully protect)
- Bind mount access to system directories
- Publicly accessible AI agent servers (an estimated 245,000+ OpenClaw instances are exposed on the internet)
Mitigation and Patching
Step 1: Update Immediately
Upgrade OpenClaw to version 2026.6.6 or later. This is the only complete fix for all three vulnerabilities.
Step 2: Restrict Channel-Facing Agents
- Enable Sandbox Mode for all non-main sessions
- Remove "exec" from the tool allowlist for channel-facing agents (WhatsApp, Slack, Discord)
- Monitor for git clone commands containing the
ext::external protocol helper, which can be abused to run arbitrary system commands
Step 3: Tighten Gateway Configuration
- Keep channel and tool allowlists narrow
- Avoid sharing one Gateway between mutually untrusted users
- Disable the affected features when they are not needed
Step 4: Monitor for Compromise
- Check for unexpected bind mounts in container logs
- Audit SSH authorized_keys files for unauthorized additions
- Review cloud provider access logs for API calls from unfamiliar IPs
Detection
Signs that an OpenClaw instance may have been compromised:
- Unexpected SSH keys in
~/.ssh/authorized_keys - New cloud provider API keys or IAM roles created
- Docker socket access from unexpected processes
- Unusual outbound network connections from the host running OpenClaw
- Modified or new cron jobs and systemd services
Frequently Asked Questions
Q: Does this affect all AI agent platforms or just OpenClaw? A: These specific CVEs affect OpenClaw, but the class of vulnerability -- insufficient sandbox isolation, command injection in execution environments, and path traversal in mount systems -- is common across many AI agent platforms. Developers should review their AI tooling's sandbox architecture.
Q: Can this be exploited without WhatsApp? A: Yes. While the proof-of-concept chain uses WhatsApp as the entry point, any channel that feeds untrusted input to an OpenClaw agent (Slack, Discord, Telegram, HTTP API) could theoretically serve as the attack vector.
Q: Does Sandbox Mode fully protect me? A: No. The bind mount bypass (GHSA-575v-8hfq-m3mc) is specifically designed to circumvent sandbox restrictions. Update to 2026.6.6 and apply the configuration hardening steps above.
Q: How many OpenClaw instances are exposed? A: Security researchers estimate over 245,000 OpenClaw instances are publicly accessible on the internet, making this a significant attack surface.
Key Takeaways
- Three high-severity OpenClaw vulnerabilities (CVSS 8.8, 8.8, 8.4) enable a WhatsApp-to-host attack chain
- The bind mount bypass lets attackers read SSH keys, AWS credentials, and escape the sandbox
- All three are patched in OpenClaw 2026.6.6 -- update immediately
- Restrict tool allowlists and enable Sandbox Mode as defense-in-depth
- This is the latest in a growing wave of AI agent security disclosures, highlighting how quickly the attack surface is expanding
Sources:
- The Hacker News: Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
- OpenClaw GitHub Security Advisories
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.