BrokenClaw – RCE in OpenClaw via Gmail Hook(veganmosfet.codeberg.page) |
BrokenClaw – RCE in OpenClaw via Gmail Hook(veganmosfet.codeberg.page) |
Main issue: OpenClaw injects untrusted content in user messages instead of using the tool channel (less authoritative) when using the Gmail webhook.
Original links:
https://veganmosfet.codeberg.page/posts/2026-02-02-openclaw_...
https://veganmosfet.codeberg.page/posts/2026-02-15-openclaw_...