Home
360's AI Agent Exposes Critical OpenClaw Flaws, Raising New Security Risks for AI-Native Apps

]On April 7, 360's Vulnerability Mining Intelligent Agent reported three critical security flaws in the AI agent OpenClaw, one classified as high-severity and two as medium-severity. All vulnerabilities were officially patched and disclosed. This milestone demonstrates a shift from rule-based to intelligent, thought-driven automated security audits, offering essential support for securing AI-native applications.
The high-severity flaw targets the approval and execution mechanism of local scripts, allowing attackers to execute unauthorized code by modifying already-approved scripts and compromising user devices. The two medium-severity issues involve reuse of security verification parameters in OAuth manual authorization and resource management weaknesses during WebSocket data processing in voice calls. The first could expose users' Google service account credentials, while the second may trigger resource exhaustion leading to device crashes. These vulnerabilities strike at the core operations of AI agents, revealing significant risks in permission isolation and protocol implementation.
360 reports that its vulnerability mining intelligent agent has discovered multiple high-value flaws across several mainstream AI agents. Unlike conventional scanning tools, this system mimics security experts' attack-defense intuition, automating detection, verification, and reproduction of vulnerabilities—freeing human analysts for more creative risk assessment. As AI agents become embedded in user workflows, AI-powered automated vulnerability discovery will serve as critical infrastructure for securing the AI supply chain's foundational layers, driving the industry toward more resilient security defenses.
Related article
ByteDance’s Seed launches global campus drive, offering virtual shares to win top large model talent
In the competitive landscape of large language models, securing top-tier talent remains the most critical strategic asset.On April 1st, ByteDance announced the launch of its Seed global campus recruitment initiative, part of its large model talent de
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a
Related Special Topic Recommendations
Comments (0)
0/500

]On April 7, 360's Vulnerability Mining Intelligent Agent reported three critical security flaws in the AI agent OpenClaw, one classified as high-severity and two as medium-severity. All vulnerabilities were officially patched and disclosed. This milestone demonstrates a shift from rule-based to intelligent, thought-driven automated security audits, offering essential support for securing AI-native applications.
The high-severity flaw targets the approval and execution mechanism of local scripts, allowing attackers to execute unauthorized code by modifying already-approved scripts and compromising user devices. The two medium-severity issues involve reuse of security verification parameters in OAuth manual authorization and resource management weaknesses during WebSocket data processing in voice calls. The first could expose users' Google service account credentials, while the second may trigger resource exhaustion leading to device crashes. These vulnerabilities strike at the core operations of AI agents, revealing significant risks in permission isolation and protocol implementation.
360 reports that its vulnerability mining intelligent agent has discovered multiple high-value flaws across several mainstream AI agents. Unlike conventional scanning tools, this system mimics security experts' attack-defense intuition, automating detection, verification, and reproduction of vulnerabilities—freeing human analysts for more creative risk assessment. As AI agents become embedded in user workflows, AI-powered automated vulnerability discovery will serve as critical infrastructure for securing the AI supply chain's foundational layers, driving the industry toward more resilient security defenses.
ByteDance’s Seed launches global campus drive, offering virtual shares to win top large model talent
In the competitive landscape of large language models, securing top-tier talent remains the most critical strategic asset.On April 1st, ByteDance announced the launch of its Seed global campus recruitment initiative, part of its large model talent de
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a











