CT
CyberTimes
HomeThreat WatchCVE-2026-25253
Vulnerability Advisory

CVE-2026-25253

Two security teams showed OpenClaw AI agent can be tricked into running attacker code or leaking AWS keys through a shared contact or plain email. Update to 2026.4.23 immediately.

Severity
high
CVSS Score
8.4 / 10
Fix Status
Patch available
Exploitation
Actively exploited
Published
Jun 12, 2026

Key Facts

  • Two independent security research teams — Imperva and Varonis — published separate findings this week showing OpenClaw AI agent can be tricked into running attacker-controlled code or forwarding your AWS keys, database credentials, and customer data through nothing more than a shared contact or a convincing email
  • Imperva buried hidden instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them — the fix is in OpenClaw 2026.4.23
  • Varonis sent a single plain email pretending to be a team lead and watched the agent forward mock AWS IAM keys, database connection strings, and SSH credentials in plaintext — this weakness cannot be fixed with a patch
  • OpenClaw has now published over 255 GitHub Security Advisories since launching late last year — and the Dutch data protection authority has warned organisations not to run it on systems holding sensitive data

Full Analysis

OpenClaw AI Agent Attacks — Hidden Commands in a Contact Card Can Steal Your AWS Keys

Deep-dive: technical breakdown, real-world impact, complete remediation steps, and expert context.

Read the full report →
← All threat reportsAll articles