PANews reported on March 31 that, according to Jinshi, 360 Digital Security Group recently discovered a high-risk vulnerability in the OpenClaw platform using itsPANews reported on March 31 that, according to Jinshi, 360 Digital Security Group recently discovered a high-risk vulnerability in the OpenClaw platform using its

360 AI Agent discovered a high-risk vulnerability in OpenClaw, potentially affecting 170,000 instances worldwide.

2026/03/31 12:44
1 min read
For feedback or concerns regarding this content, please contact us at [email protected]

PANews reported on March 31 that, according to Jinshi, 360 Digital Security Group recently discovered a high-risk vulnerability in the OpenClaw platform using its independently developed 360 Multi-Agent Collaborative Vulnerability Discovery System—a MEDIA protocol Prompt injection vulnerability that bypasses tool privileges and leaks local files. This vulnerability has been officially confirmed by the China National Vulnerability Database (CNNVD), affecting more than 50 countries and regions worldwide, with over 170,000 publicly accessible OpenClaw instances at risk. The core risk of this vulnerability lies in the fact that the MEDIA protocol runs at the output post-processing layer, completely bypassing platform tool policy controls. Even if the agent disables all tool calls, attackers can launch attacks with only basic group chat member privileges, directly stealing sensitive server information and easily triggering subsequent network attacks.

Market Opportunity
Prompt Logo
Prompt Price(PROMPT)
$0,02976
$0,02976$0,02976
-0,73%
USD
Prompt (PROMPT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.