Express

China Information and Communication Research Institute, in collaboration with universities, discovers and fixes high-risk command injection vulnerability in OpenClaw

Summary: According to market reports, a joint team from China Information and Communication Research Institute, Shanghai Jiao Tong University, and Nanjing University discovered a high-risk command injection vulnerability in the bash-tools module of the open-source autonomous agent framework OpenClaw during a security audit. The vulnerability stems from the system not strictly escaping command line parameters generated ...

According to market reports, a joint team from China Information and Communication Research Institute, Shanghai Jiao Tong University, and Nanjing University discovered a high-risk command injection vulnerability in the bash-tools module of the open-source autonomous agent framework OpenClaw during a security audit. The vulnerability stems from the system not strictly escaping command line parameters generated by LLM, allowing attackers to bypass regular defenses through misleading prompts, achieve remote code execution on the host machine, and steal sensitive data. The research team has completed attack verification in multiple mainstream model environments, initiated responsible vulnerability disclosure procedures, and submitted repair suggestions to the NVDB Artificial Intelligence Product Security Vulnerability Database (CAIVD) and the GitHub community.

  • The Road to 2026: Where Is the Web3 Ecosystem Heading Next? December 7, 2025
  • Vishwa Advances Agentic Infrastructure Research Through Contribution to Emerging Framew... November 22, 2025
  • BitMart US Launches Operations with 49-State Licensing and Zero-Fee Program November 17, 2025
  • Global Financial Giants Enter Stablecoin Arena in Pivotal Shift October 30, 2025
  • CRYPTO'S NEW PLAY: 24/7 STOCK TRADING October 29, 2025
  • You need to login to comment.