The China Academy of Information and Communications Technology collaborates with universities to discover and fix the high-risk command injection vulnerability in OpenClaw
The China Academy of Information and Communications Technology, in collaboration with Shanghai Jiao Tong University and Nanjing University, discovered a high-risk vulnerability driven by LLM command injection in the bash-tools module of the open-source autonomous intelligent agent framework OpenClaw during a security audit.
This vulnerability arises from the system's failure to strictly escape command line parameters generated by LLM, allowing attackers to bypass regex defenses through inducive prompts, achieving remote code execution on the host machine and stealing sensitive data.
The research team has completed attack verification in various mainstream model environments, initiated a responsible vulnerability disclosure process, and submitted repair suggestions to the NVDB Artificial Intelligence Product Security Vulnerability Professional Database (CAIVD) and the GitHub community.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Thomson Reuters Develops Legal AI Model 'Thomson' with $40 Million Investment

Strategy Launches USD Cash Liquidity Account with $1.59 Billion Balance

Anthropic Invests $35 Million in Security Fund to Expand Claude Mythos 5's Defensive Capabilities

D2 Finance Raises Five Questions on Tori Finance's Gap-Filling Actions

NVIDIA to Report Quarterly Earnings This Wednesday, Surpassing Expectations for 14 Consecutive Quarters

Anthropic Highlights AI Sentiment Risks in IPO Prospectus

Polymarket News Reaction Rate at 15.2%, Variations by Source

Qwen 3.8-27B Surpasses Muse Glimmer, Approaches Claude Opus 4.6

Mixedbread Unveils Search Agent Toast 1

X Open Source For You Timeline Visibility Code Launches Label Transparency Tool

White House Plans to Expand AI Regulation, Open Source Models to be Included in Testing Framework

Foreign Media: Three AI Pioneers Oppose Comprehensive Tightening of Open Models

Oracle Partners with Quantinuum to Integrate Quantum Computing into OCI Cloud Platform

Ethereum Foundation Transfers 566.27 ETH Worth Approximately $1.09 Million

Meta Launches Open Source AI Model Muse Glimmer

Brazilian Court Rejects Hacker Suspect's Release Request in $160 Million Money Laundering Case

Wildberries Launches Partnership Program for Hub Openings

Pally Secures $5.2 Million Funding Led by Cyber Fund and Y Combinator

Zuckerberg: Every Business Will Have Its Own AI System in the Future

Proof of Play Closes, Web3 Game Developer Founded by Amitt Mahajan

Alpaca's Monthly API Users Quadruple in Six Months

Coinbase AI Programming System Forge Becomes Core Component of OpenSWE

U.S. Will Not Ban Chinese Open-Source Models for Now

Proof of Play Ceases Operations, Open Sources Pirate Nation Code and Art Assets

Bitcoin Red Team Scans 150 Code Repositories, Discovers Over a Dozen Critical Vulnerabilities

National Supercomputing Internet Launches DeepSeek-V4-Flash API

DeepSeek Harness Begins Beta Testing, Recruiting Open Source Project Developers

Suno Loses Copyright Case in Germany

Moonshot AI Utilizes 20,000 NVIDIA Chips Through Alibaba





