Security researcher Chinmohan Nayak has disclosed details of three now-patched, high-severity vulnerabilities in the OpenClaw personal artificial intelligence assistant that, when chained, allowed for remote code execution on the host system via an external WhatsApp message. These flaws, identified as GHSA-hjr6-g723-hmfm (CVSS 8.8), GHSA-9969-8g9h-rxwm (CVSS 8.8), and GHSA-575v-8hfq-m3mc (CVSS 8.4), collectively enabled credential theft, privilege escalation, and arbitrary code execution. All three issues have been addressed in OpenClaw version 2026.6.6.