PANews reported on March 22 that, according to Jinshi, the 360 ​​Security Cloud team received an official email from Peter, the founder of OpenClaw. In his replyPANews reported on March 22 that, according to Jinshi, the 360 ​​Security Cloud team received an official email from Peter, the founder of OpenClaw. In his reply

OpenClaw founder confirms in reply that 360 was the exclusive discoverer of the vulnerability.

2026/03/22 17:05
1 min read
For feedback or concerns regarding this content, please contact us at [email protected]

PANews reported on March 22 that, according to Jinshi, the 360 ​​Security Cloud team received an official email from Peter, the founder of OpenClaw. In his reply, Peter officially confirmed the OpenClaw Gateway WebSocket unauthenticated upgrade vulnerability, which was exclusively discovered by the 360 ​​team.

Currently, 360 has simultaneously reported this high-risk vulnerability to the National Information Security Vulnerability Sharing Platform (CNVD) to assist the entire network in cutting off the source of the risk as soon as possible. The WebSocket unauthenticated upgrade vulnerability confirmed this time is a zero-day vulnerability. Attackers can use this vulnerability to silently bypass authorization authentication through WebSocket, gain control of the smart agent gateway, and may lead to the exhaustion of target system resources or complete crash.

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.03802
$0.03802$0.03802
-0.60%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.