About this talk
This talk dissects a 1-click Remote Code Execution (RCE) chain in OpenClaw, where the speaker, Mav Levin, explores a configuration logic vulnerability alongside a Cross-Site WebSocket Hijacking flaw. The session details how these vulnerabilities can be combined to effectively bypass network defenses, sandboxing mechanisms, and user approval processes to take control of AI assistants. Through this analysis, attendees gain insights into the critical security implications surrounding modern AI technologies.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30