A high-risk vulnerability has been identified in the OpenClaw platform, according to PANews. The discovery was made by the 360 Digital Security Group, which developed the 360 Multi-Agent Collaborative Vulnerability Mining System. The flaw, known as the MEDIA protocol prompt injection bypass tool permission leak local file vulnerability, has been officially confirmed by the National Information Security Vulnerability Database (CNNVD).
This vulnerability affects over 170,000 publicly accessible OpenClaw instances across more than 50 countries and regions worldwide. The core risk lies in the MEDIA protocol operating at the output post-processing layer, allowing attackers to bypass platform tool policy controls. Even if an agent disables all tool calls, attackers can exploit basic group chat member permissions to initiate attacks and directly steal sensitive server information, potentially leading to further cyber attacks.