Tag: OpenClaw Bug

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
News

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

OpenClaw (previously known as Clawdbot and Moltbot) has been found to have a high-severity security vulnerability that could enable remote code execution (RCE) via a malicious link. Version 2026.1.29, which was issued on January 30, 2026, fixes the problem, which is tracked as CVE-2026-25253 (CVSS score: 8.8). According to some descriptions, it is a token exfiltration vulnerability that results in complete gateway compromise. According to an advice from Peter Steinberger, the inventor and manager of OpenClaw, the Control UI automatically connects upon load by delivering the stored gateway token in the WebSocket connect payload, trusting gatewayUrl from the query string without validation. The token can be sent to a server under the control of the attacker by clicking on a malicio...