{"id":1703,"date":"2026-07-10T16:27:57","date_gmt":"2026-07-10T16:27:57","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1703"},"modified":"2026-07-10T16:27:57","modified_gmt":"2026-07-10T16:27:57","slug":"researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1703","title":{"rendered":"Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 10, 2026<\/span><\/span><span class=\"p-tags\">AI Security \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgs80_SEcGa8Q18LOUd4Y3fWiWZRh6MOX6U3LhAyAVVewqJVSd1cq2bgepE_2vS0eg9qvr0iM1JOYnYd9GPDQ-LZiTP4-J8oEpZjAMc2ivQ9QiNTMbf1BYONSvBOvZaVat_1PUWjM9O72K_pdF74UKhHm-dd-wXKLp8BDoV4dQZTi1HWOUCWbozpd4muH0i\/s1700-e365\/openclaw-whatsapp.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Details have emerged about three now-patched <a href=\"https:\/\/github.com\/jgamblin\/OpenClawCVEs\/\" target=\"_blank\">security flaws<\/a> in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.<\/p>\n<p>A brief description of the high-severity vulnerabilities is as follows\u00a0&#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/github.com\/openclaw\/openclaw\/security\/advisories\/GHSA-hjr6-g723-hmfm\" target=\"_blank\">GHSA-hjr6-g723-hmfm<\/a><\/strong> (CVSS score: 8.8) &#8211; An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller&#8217;s intended authorization.<\/li>\n<li><strong><a href=\"https:\/\/github.com\/openclaw\/openclaw\/security\/advisories\/GHSA-9969-8g9h-rxwm\" target=\"_blank\">GHSA-9969-8g9h-rxwm<\/a><\/strong> (CVSS score: 8.8) &#8211; An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller&#8217;s intended authorization.<\/li>\n<li><strong><a href=\"https:\/\/github.com\/openclaw\/openclaw\/security\/advisories\/GHSA-575v-8hfq-m3mc\" target=\"_blank\">GHSA-575v-8hfq-m3mc<\/a><\/strong> (CVSS score: 8.4) &#8211; A path traversal and link following vulnerability that could allow <a href=\"https:\/\/arxiv.org\/abs\/2603.27517\" target=\"_blank\">sandbox bind mounts<\/a> to bypass parent-directory denylist checks and perform actions that should have been secured with stronger authorization or policy checks.<\/li>\n<\/ul>\n<p>All three shortcomings have been addressed in OpenClaw version 2026.6.6.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg7pp31YSx7YW04s7vxzEYFYsk_y-4ncrMNOtkTw28tuuYW4vjWPb7P9mAe1Ubpa1OPfMIe-nIE6QxtkBjL4J4gvNFanwEZhtdtDuOApElzQf863NGWbHs6CKe6elnjDZXDKA0jiWQfjDoPYamSHzrfpcy11qEMoIbR6iDsq4hAf2REYGHRZYIiZQ1TgF39\/s1700-e365\/open.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg7pp31YSx7YW04s7vxzEYFYsk_y-4ncrMNOtkTw28tuuYW4vjWPb7P9mAe1Ubpa1OPfMIe-nIE6QxtkBjL4J4gvNFanwEZhtdtDuOApElzQf863NGWbHs6CKe6elnjDZXDKA0jiWQfjDoPYamSHzrfpcy11qEMoIbR6iDsq4hAf2REYGHRZYIiZQ1TgF39\/s1700-e365\/open.jpg\" alt=\"\" border=\"0\" data-original-height=\"310\" data-original-width=\"1400\"\/><\/a><\/div>\n<p>In a series of advisories released last week, OpenClaw maintainers said \u00abpractical impact depends on the operator&#8217;s configuration and whether lower-trust input can reach that path.\u00bb<\/p>\n<p>However, security researcher Chinmohan Nayak, who is credited with discovering and reporting the issues, said in a <a href=\"https:\/\/medium.com\/@chinmohannayak\/i-sent-a-whatsapp-message-to-an-ai-agent-it-ran-my-code-on-the-host-adbbcbb0e0ad\" target=\"_blank\">report<\/a> shared with The Hacker News that they can be used to trigger host code execution from an external message sent via WhatsApp.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEju3jGYADeL_1dA8qwtLpzzGKgBpklCfIGmjeMoJlxtlSMdez1q7uss-H9gaBSiqYtSHQjOCbKLifZxOe6GCWnueNFLZKR6pyYKfkc7kZWWQQXm_E7Wi9IH2E-SfActpcfBBZm_-aX4pVUmKslXQIZ1z4hwq8WX0JFdMxcFVRNAll_-n6Fj0a1Fi9MKMkK5\/s1700-e365\/whatsapp-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEju3jGYADeL_1dA8qwtLpzzGKgBpklCfIGmjeMoJlxtlSMdez1q7uss-H9gaBSiqYtSHQjOCbKLifZxOe6GCWnueNFLZKR6pyYKfkc7kZWWQQXm_E7Wi9IH2E-SfActpcfBBZm_-aX4pVUmKslXQIZ1z4hwq8WX0JFdMxcFVRNAll_-n6Fj0a1Fi9MKMkK5\/s1700-e365\/whatsapp-ai.jpg\" alt=\"\" border=\"0\" data-original-height=\"639\" data-original-width=\"720\"\/><\/a><\/div>\n<p>Unlike the Claw Chain vulnerabilities disclosed by Cyera back in May, the newly identified bugs do not require an attacker to establish a prior foothold in order to extract sensitive data, drop a persistent backdoor, obtain arbitrary remote code execution, and facilitate an escape to the host.<\/p>\n<p>\u00ab`getBlockedReasonForSourcePath()` checks if the source path is under a blocked path,\u00bb the researcher explained about GHSA-575v-8hfq-m3mc. \u00abBut [it] never checks the reverse \u2014 whether a blocked path is under the source (parent directory bypass).\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Specifically, the bind mount denylist blocks directories like \u00ab~\/.ssh,\u00bb \u00ab~\/.aws,\u00bb and \u00ab~\/.gnupg,\u201d but allows mounting the parent directory \u00ab\/home\u00bb or \u00ab\/var,\u00bb effectively undermining the individual blocks.<\/p>\n<p>\u00abMount \/home into your container, and you can read every user&#8217;s SSH keys, AWS credentials, and GPG secrets,\u00bb Nayak said. \u00abMount \/var and you get the Docker socket \u2013 which means full host escape from inside the &#8216;sandbox.'\u00bb<\/p>\n<p>Besides updating OpenClaw to the latest version, it&#8217;s advised to enable sandbox mode for all non-main sessions, remove \u00abexec\u00bb from the tool allowlist for channel-facing agents, and monitor for git clone commands containing the \u00abext::\u00bb external protocol helper that could be abused to run arbitrary system commands.<\/p>\n<p>\u00abBefore upgrading, restrict the affected feature to trusted operators or disable it when it is not needed,\u00bb OpenClaw said. \u00abAs general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 10, 2026AI Security \/ Vulnerability Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1704,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[220,219,1065,11,222,1824,2470],"class_list":["post-1703","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attack","tag-chain","tag-details","tag-flaws","tag-openclaw","tag-researcher","tag-whatsapptohost"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1703"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1703\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1704"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}