highZero-Day

OpenClaw AI Assistant WhatsApp-to-Host Attack Chain

First seen Jul 13, 2026 · Updated Jul 13, 2026 · CVSS 8.8

agent-relevantai-assistantprivilege-escalationrcecredential-theftmessaging-app-exploitopenclaw

Security researchers disclosed a chained exploit involving three now-patched vulnerabilities in the OpenClaw personal AI assistant that could be triggered via WhatsApp messages to achieve credential theft, privilege escalation, and arbitrary code execution on the host system. The attack chain leverages the assistant's integration with messaging platforms as an entry point, ultimately compromising the underlying host running the AI agent.

Technical Analysis

The disclosed attack chain includes GHSA-hjr6-g723-hmfm (CVSS 8.8), an OS-level flaw that appears to enable command injection or improper input sanitization when OpenClaw processes messages received via WhatsApp integration. Combined with two additional undisclosed high-severity flaws, the chain allows an attacker to escalate from a remote messaging vector to full host compromise, including theft of stored credentials and arbitrary code execution. This is a direct example of an agent-relevant threat: OpenClaw operates as a personal AI assistant with tool-use and messaging integrations, meaning successful exploitation could expose API keys, session tokens, and other credentials the agent uses to interact with connected services, and grant attackers control over the host executing the agent's automation tasks.

Affected Systems

OpenClaw personal AI assistant (versions prior to patch release), hosts running OpenClaw with WhatsApp integration enabled

Indicators of Compromise

  • No specific file hashes, IPs, or domains disclosed in source reporting

Remediation Steps

  1. 1

    Apply vendor patches

    Update OpenClaw to the latest patched version addressing GHSA-hjr6-g723-hmfm and related vulnerabilities immediately.

  2. 2

    Restrict messaging integrations

    Disable or tightly scope WhatsApp and other third-party messaging integrations for AI assistants until patches are confirmed applied.

  3. 3

    Rotate credentials

    Rotate API keys, tokens, and credentials accessible to the AI assistant in case of prior exploitation.

  4. 4

    Audit host permissions

    Ensure AI assistant processes run with least-privilege access and are isolated from sensitive host resources.

  5. 5

    Monitor for anomalous activity

    Review logs for unexpected code execution, privilege escalation attempts, or unusual outbound connections from hosts running OpenClaw.

CVE / Advisory IDs

GHSA-hjr6-g723-hmfm

Industries Most Exposed

technologyconsumersoftware-development

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.