top | item 46913892

0-Click Remote Code Execution in OpenClaw with GPT5.2 via Gmail Hook

4 points| veganmosfet | 24 days ago |veganmosfet.github.io

3 comments

order

veganmosfet|24 days ago

Yet another "OpenClaw is insecure" post! I found this simple but elegant way to get silent RCE via email, exploiting prompt injection (despite countermeasures, there is no silver bullet) and insecure plugin handling (not skills!). I try to explain how it works and some ideas about hardening. Note: prompt injection attacks are out-of-scope in the security policy. Happy to get feedback.

veganmosfet|22 days ago

[Update] Now with opus4.6 and latest version.