
🚨 LIVE HIJACK ALERT — CVE-2026-35629. CVSS 7.4. openclaw agents can be tricked into fetching internal resources they should never touch. attackers redirect your configured endpoints to localhost, cloud metadata, internal APIs. your agent becomes their pivot point. investigating. 🧵
Post summary
OpenClaw agents are being actively hijacked via misdirected endpoints, turning them into pivot points for attackers under CVE-2026-35629, which carries a CVSS score of 7.4.



