OpenClaw: 3 vulnerabilities from WhatsApp to host takeover

Colleagues, a cybersecurity issue to note.
Researchers found three patched OpenClaw flaws that could enable credential theft, privilege escalation, and host code execution.
The chain could even be triggered by a WhatsApp message.
Path-check bypasses and command injection may expose secrets and enable sandbox escape.
What to do:
- upgrade to OpenClaw 2026.6.6
- enable sandboxing for non-primary sessions
- remove exec from the allowlist
- monitor git clone with ext::
Why it matters: in AI assistants, such flaws can turn a trusted channel into a compromise point.
Have you reviewed your allowlist and sandbox policies in AI tools? #cybersecurity #AIsecurity #vulnerability #OpenSource

