A high-severity flaw in OpenClaw (also known as Clawdbot / Moltbot) enables one-click remote code execution (RCE) by abusing how the Control UI auto-connects to a gateway specified via a crafted URL. The issue is tracked as CVE-2026-25253 (CVSS 8.8) and was fixed in OpenClaw 2026.1.29; the core weakness is that the UI trusts gatewayUrl from the query string and sends a stored gateway token in the WebSocket connection payload, allowing token exfiltration to an attacker-controlled server.
With the stolen token, an attacker can connect to the victim’s local gateway and perform privileged actions—such as modifying configuration (e.g., sandbox/tool policies) and invoking privileged operations—resulting in full gateway compromise and RCE. Separate reporting also highlights architectural risk in OpenClaw’s local WebSocket-based Chrome orchestration, noting that (prior to patching) unauthenticated connections could be initiated from JavaScript running in a user’s browser, enabling cross-tab/session credential theft; users are advised to patch immediately and be cautious about deployment given ongoing security concerns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, security coverage from multiple sources warned that malicious websites could steal OpenClaw session credentials and lead to full system compromise. Users were advised to upgrade to version 2026.1.29, rotate tokens and secrets, and audit for suspicious WebSocket activity.
Public reporting described how OpenClaw's Control UI trusted a gatewayUrl parameter, leaked an auth token over WebSocket, and allowed cross-site WebSocket hijacking because the server did not validate the Origin header. The disclosed attack chain showed how attackers could disable approvals, force host execution, and run arbitrary commands.
OpenClaw maintainer Peter Steinberger disclosed that the issue was fixed in OpenClaw version 2026.1.29, released on January 30, 2026. The patch addressed the flaw later tracked as CVE-2026-25253 affecting versions prior to 2026.1.29.
Security researcher Mav Levin of depthfirst reported a high-severity OpenClaw vulnerability that could lead to one-click remote code execution through authentication token exfiltration and WebSocket abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcereddit.com
Open sourcethehackernews.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.