Settings

Theme

0-Click Remote Code Execution in OpenClaw with GPT5.2 via Gmail Hook

veganmosfet.github.io

4 points by veganmosfet 2 months ago · 3 comments

Reader

veganmosfetOP a month ago

Second part of the saga, now escaping sandbox with multi-layered prompt injection:

BrokenClaws: Escape the Sub-Agent Sandbox with Indirect Prompt Injection in OpenClaw (via Gmail Hook, 0-Click RCE)

https://veganmosfet.github.io/2026/02/15/openclaw_sandbox.ht...

veganmosfetOP 2 months ago

Yet another "OpenClaw is insecure" post! I found this simple but elegant way to get silent RCE via email, exploiting prompt injection (despite countermeasures, there is no silver bullet) and insecure plugin handling (not skills!). I try to explain how it works and some ideas about hardening. Note: prompt injection attacks are out-of-scope in the security policy. Happy to get feedback.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection