Skip to main content
VerifiedOverreach

ClawJacked, where any website a user visited could pair itself with their local agent and drive it

Oasis Security disclosed in February 2026 that a widely installed local agent exposed a gateway on the loopback address which browsers do not block across origins. The gateway exempted local connections from rate limiting and auto approved their device pairing, so any page a user visited could guess the password, register itself as trusted, and then operate the agent.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0016
Kind
Overreach
Jurisdiction
Global
Last verified
Added
  • Oasis Security states that once paired, the attacker has full control and can interact with the agent, dump configuration data, enumerate connected devices and read logs.
  • The research states there is no rate limit and no failure limit for password guesses arriving from the loopback address.
  • The gateway auto approved device pairings from the loopback address with no prompt to the user.
  • The design treated a connection from the local machine as proof of identity, which a browser can satisfy from any web page.
  • A fixed version was published within about a day of the disclosure.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
A connection from the local machine was treated as proof of identity, which any web page can produce.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
AuthorizationSilent
A newly paired device received full agent permissions with no scoping.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
LimitsSilent
The research states there was no rate or failure limit on password guesses from the loopback address.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
Human approvalSilent
Pairing was auto approved with no user prompt, so the one moment a human could have refused was removed.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
Logging and auditOpen
Logs existed and were readable by the attacker, but nothing alerted the user to a new paired device.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
RevocationStated
A patched version shipped within about a day of the report.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
AccountabilityStated
Named researchers, a coordinated disclosure and a vendor fix.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.

What it changes

For a team deploying an agent

Loopback is not an authentication boundary once a browser is on the same machine. If you run a local agent, the controls that matter are identity and human approval: require an explicit pairing confirmation for every new client, rate limit authentication from every origin including the local one, and put the agent's console behind a credential you did not accept by default.

Sources

What this record was verified against

  1. Oasis Security, ClawJacked vulnerability disclosurePrimary · 26 February 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0016 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), clawjacked, where any website a user visited could pair itself with their local agent and drive it.
APA
GAGE (Global Academy of Generative-AI Education). (2026). ClawJacked, where any website a user visited could pair itself with their local agent and drive it. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent
MLA
"ClawJacked, where any website a user visited could pair itself with their local agent and drive it." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent.
Chicago
GAGE (Global Academy of Generative-AI Education). "ClawJacked, where any website a user visited could pair itself with their local agent and drive it." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every overreach record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.