The China Academy of Information and Communications Technology collaborates with universities to discover and fix the high-risk command injection vulnerability in OpenClaw

By: rootdata|2026/03/16 20:42:00
0
Share
copy

The China Academy of Information and Communications Technology, in collaboration with Shanghai Jiao Tong University and Nanjing University, discovered a high-risk vulnerability driven by LLM command injection in the bash-tools module of the open-source autonomous intelligent agent framework OpenClaw during a security audit.

This vulnerability arises from the system's failure to strictly escape command line parameters generated by LLM, allowing attackers to bypass regex defenses through inducive prompts, achieving remote code execution on the host machine and stealing sensitive data.

The research team has completed attack verification in various mainstream model environments, initiated a responsible vulnerability disclosure process, and submitted repair suggestions to the NVDB Artificial Intelligence Product Security Vulnerability Professional Database (CAIVD) and the GitHub community.

-- Price

--

You may also like

Uniswap is trapped in an innovation dilemma

The various iterations of Uniswap are one of the sources of vitality in the DeFi market, but since 2023, Uniswap has not proposed any substantial innovations, instead adhering to traditional business explorations in application chains, Launchpads, etc., leading to a slump in token prices and market ...

What is the key to competition in crypto banking?

Digital banks, crypto cards, wallets, super apps, and DeFi protocols are all converging towards the same goal: to become the primary gateway for your savings, spending, earning, and transferring in the new era.

The flow of stablecoins and the spillover effects in the foreign exchange market

Research has found that an exogenous increase in net inflows of stablecoins significantly widens the price deviation between stablecoins and traditional foreign exchange, leads to depreciation of the local currency, and worsens the financing conditions for synthetic dollars (i.e., increases the doll...

After two years, Hong Kong's first batch of stablecoin licenses finally issued: HSBC, Standard Chartered make the cut

The regulated entity is set to launch a stablecoin in the first half of this year.

The person who helped TAO rise by 90% has now single-handedly crashed the price again today

As long as people are around, the story continues. But once they're gone, you may not even find a worthy opponent to play against.

3-Minute Guide to Participating in the SpaceX IPO on Bitget

Bitget IPO Prime brings a rare opportunity for global users to participate in world-class unicorn IPOs, allowing ordinary users to equally access the potential economic benefits of top-tier IPOs.