• News/
  • https://www.theregister.com/2025/11/23/infosec_news_in_brief/

Weaponized file name flaw allows RCE through glob

The Register
·
Brandon Vigliarolo
·
Published Nov 23, 2025
·
Updated

Infosec In Brief So-hot-right-now AI assistant OpenClaw, which is very much not secure right now, has teamed up with security scanning service VirusTotal. The tie-up means “skills” in the ClawHub – custom plugins for the OpenClaw assistant – will be scanned by over 70 antivirus scanners and URL/domain blocklisting services. “OpenClaw skills are powerful. They extend what your AI agent can do—from controlling smart home devices to managing finances to automating workflows. But with that power comes risk,” the assistant’s developers wrote in a Saturday post that explains the decision to work with VirusTotal. The post points out that working with the scanning service won’t totally secure OpenClaw. “Let’s be clear: this is not a silver bullet,” the developers wrote. “VirusTotal scanning won’t catch everything. A skill that uses natural language to instruct an agent to do something malicious won’t trigger a virus signature. A carefully crafted prompt injection payload won’t show up in a threat database.” Fallout from the Salt Typhoon hack of leading American telcos continues, and one US Senator isn't convinced that victim companies are being honest. Senator Maria Cantwell (D-WA), the ranking member of the Senate Committee on Commerce, Science, and Transportation, last week sent a letter to her Republican counterpart demanding the CEOs of AT&T and Verizon appear before the group to explain why they keep withholding security assessments performed in the wake of 2024 revelations of w...

Read full article

Affected Software

3 affected components
SmarterTools SmarterMail=2025-52691
SmarterTools SmarterMail=2026-23760
SmarterTools SmarterMail=2026-24423
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in the AI assistant OpenClaw that allows for remote code execution (RCE) through weaponized file names.

2

What security implications are discussed in the article?

The article highlights the threat of remote code execution attacks stemming from a flaw in OpenClaw's handling of file names.

3

What software is specifically mentioned as being affected by this vulnerability?

The software specifically mentioned as being affected is SmarterTools SmarterMail.

4

What measures are being taken to mitigate the risks associated with this vulnerability?

The partnership between OpenClaw and VirusTotal aims to scan custom plugins for security vulnerabilities using over 70 antivirus scanners.

5

When was the vulnerability reported and subsequently modified in the article?

The vulnerability was reported on November 23, 2025, and modified the following day on November 24, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203