The 360 intelligent system discovered a high-risk vulnerability in OpenClaw, potentially affecting 170,000 instances globally.
Sina Finance News on March 31, recently learned from 360 Digital Security Group that its independently developed 360 Intelligent Collaborative Vulnerability Discovery System discovered a critical vulnerability in the MEDIA protocol Prompt injection bypass tool permission leakage local file vulnerability in the OpenClaw platform. This vulnerability has been formally confirmed by the National Information Security Vulnerability Database, affecting over 50 countries and regions globally, with over 170,000 publicly accessible OpenClaw instances facing security risks. It is reported that the core risk of this vulnerability lies in the fact that the MEDIA protocol runs at the output post-processing layer, bypassing platform tool policy control completely. Even if the Agent disables all tool calls, attackers can launch attacks with only basic group member permissions, directly stealing sensitive information from the server, and easily triggering subsequent network attacks.
Latest

