PT-2026-5584 · Openclaw · Openclaw
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.1.29
Description
OpenClaw (also known as ClawdBot or MoltBot) contains a critical security flaw due to the lack of proper validation of incoming requests. The software obtains a
gatewayUrl value from a query string and automatically establishes a WebSocket connection without user prompting, which transmits a token value. This flaw allows a remote attacker to gain unauthorized system access and execute arbitrary code if a user visits a specially crafted link. This issue is characterized as a WebSocket token hijacking vulnerability.Recommendations
Update OpenClaw to version 2026.1.29 or later.
Exploit
Fix
RCE
LPE
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw