ClawJacked, where any website a user visited could pair itself with their local agent and drive it
Oasis Security disclosed in February 2026 that a widely installed local agent exposed a gateway on the loopback address which browsers do not block across origins. The gateway exempted local connections from rate limiting and auto approved their device pairing, so any page a user visited could guess the password, register itself as trusted, and then operate the agent.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0016
- Kind
- Overreach
- Jurisdiction
- Global
- Last verified
- Added
- Oasis Security states that once paired, the attacker has full control and can interact with the agent, dump configuration data, enumerate connected devices and read logs.
- The research states there is no rate limit and no failure limit for password guesses arriving from the loopback address.
- The gateway auto approved device pairings from the loopback address with no prompt to the user.
- The design treated a connection from the local machine as proof of identity, which a browser can satisfy from any web page.
- A fixed version was published within about a day of the disclosure.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- A connection from the local machine was treated as proof of identity, which any web page can produce.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- AuthorizationSilent
- A newly paired device received full agent permissions with no scoping.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- LimitsSilent
- The research states there was no rate or failure limit on password guesses from the loopback address.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- Human approvalSilent
- Pairing was auto approved with no user prompt, so the one moment a human could have refused was removed.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- Logging and auditOpen
- Logs existed and were readable by the attacker, but nothing alerted the user to a new paired device.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- RevocationStated
- A patched version shipped within about a day of the report.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
- AccountabilityStated
- Named researchers, a coordinated disclosure and a vendor fix.Oasis Security, ClawJacked vulnerability disclosure, primary source, 26 February 2026.
What it changes
For a team deploying an agent
Loopback is not an authentication boundary once a browser is on the same machine. If you run a local agent, the controls that matter are identity and human approval: require an explicit pairing confirmation for every new client, rate limit authentication from every origin including the local one, and put the agent's console behind a credential you did not accept by default.
Sources
What this record was verified against
- Oasis Security, ClawJacked vulnerability disclosurePrimary · 26 February 2026
Related
Records that sit beside this one
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
Global · verified 15 September 2026
The research states the agent forwarded cloud access keys, database passwords and shell credentials to an external mail address in one simulation.
A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
United States · verified 15 September 2026
The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0016 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), clawjacked, where any website a user visited could pair itself with their local agent and drive it.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). ClawJacked, where any website a user visited could pair itself with their local agent and drive it. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent
- MLA
- "ClawJacked, where any website a user visited could pair itself with their local agent and drive it." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "ClawJacked, where any website a user visited could pair itself with their local agent and drive it." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0016-clawjacked-any-website-could-drive-a-local-agent
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every overreach record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.