OpenClaw has a self-attack vulnerability that mistakenly executes Bash commands, leading to key leakage

By: rootdata|2026/03/05 20:43:30
0
Share
copy

Web3 security company GoPlus stated that the AI development tool OpenClaw has recently been reported to have experienced a self-attack security incident. During the execution of automated tasks, the system constructed an incorrect Bash command while calling Shell commands to create a GitHub Issue, inadvertently triggering command injection, which led to the exposure of a large number of sensitive environment variables.

In the incident, the AI-generated string contained a set wrapped in backticks, which was interpreted by Bash as command substitution and executed automatically. Since Bash outputs all current environment variables when executing set without parameters, this ultimately resulted in over 100 lines of sensitive information (including Telegram keys, authentication tokens, etc.) being directly written to the GitHub Issue and publicly published. GoPlus recommends that in AI automation development or testing scenarios, API calls should be used instead of directly concatenating Shell commands, and the principle of least privilege should be followed to isolate environment variables. Additionally, high-risk execution modes should be disabled, and a manual review mechanism should be introduced for critical operations.

-- Price

--

You may also like

How WEEX Bridges Crypto and Football: A Deep Look at the LALIGA Partnership Inside the WEEX App

WEEX is not just a LALIGA sponsor. It’s a true partner. From iPhone Dynamic Island to LALIGA-themed app icons and smart posters, see how WEEX brings football passion into every trade — and builds a real bridge between crypto and sports.

FC Barcelona vs Real Madrid Preview: El Clásico – Can Barça Clinch the Title at Spotify Camp Nou?

FC Barcelona vs Real Madrid El Clásico match preview for May 11, 2026. Barça need just 1 point to win LALIGA. Can Madrid delay the trophy? Full preview inside.

Miners welcome a new life

Under the dual impact of the halving crisis and market crash, Bitcoin mining farms are fully transforming into AI data centers by leveraging existing power infrastructure, fiercely securing billions in orders from tech giants for a comeback.

At the Stripe conference, I saw the future of the AI economy

When agents cross the boundaries of tools and begin to make autonomous decisions and payments, a new business transformation has arrived.

Seven Important Judgments by Claude Code's Founder at the Sequoia Conference

Claude Code founder's in-depth sharing at the Sequoia Conference: AI is downgrading "coding" to a basic skill, cross-domain product insights have become the new core barrier, traditional SaaS moats are completely collapsing, and the golden era of startups disrupting large companies has already begun...

Morning Report | MoonPay acquires Solana's execution layer DFlow; Strategy releases Q1 financial report; Manta Network announces the termination of Manta staking program

Overview of Important Market Events on May 6th

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com