PT-2026-5584 · Openclaw · Openclaw

·

CVE-2026-25253

·

Published

2026-01-31

·

Updated

2026-07-13

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.1.29
Description OpenClaw (also known as ClawdBot or MoltBot) contains a critical security flaw due to the lack of proper validation of incoming requests. The software obtains a gatewayUrl value from a query string and automatically establishes a WebSocket connection without user prompting, which transmits a token value. This flaw allows a remote attacker to gain unauthorized system access and execute arbitrary code if a user visits a specially crafted link. This issue is characterized as a WebSocket token hijacking vulnerability.
Recommendations Update OpenClaw to version 2026.1.29 or later.

Exploit

Fix

RCE

LPE

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01840
CVE-2026-25253
GHSA-G8P2-7WF7-98MQ
GHSA-R2C6-8JC8-G32W

Affected Products

Openclaw