Safety Control Tampering: A New Class of Attack on AI Agents

CVE-2026-25253 revealed a 1-click RCE in OpenClaw. We analyzed the attack chain and found a pattern that goes beyond this single vulnerability — attackers disabling safety controls before exploitation.