OpenClaw Vulnerability Enables Token Exfiltration and One-Click RCE via Malicious Link
A high-severity flaw in OpenClaw (also known as Clawdbot / Moltbot) enables one-click remote code execution (RCE) by abusing how the Control UI auto-connects to a gateway specified via a crafted URL. The issue is tracked as CVE-2026-25253 (CVSS 8.8) and was fixed in OpenClaw 2026.1.29; the core weakness is that the UI trusts gatewayUrl from the query string and sends a stored gateway token in the WebSocket connection payload, allowing token exfiltration to an attacker-controlled server.
With the stolen token, an attacker can connect to the victim’s local gateway and perform privileged actions—such as modifying configuration (e.g., sandbox/tool policies) and invoking privileged operations—resulting in full gateway compromise and RCE. Separate reporting also highlights architectural risk in OpenClaw’s local WebSocket-based Chrome orchestration, noting that (prior to patching) unauthenticated connections could be initiated from JavaScript running in a user’s browser, enabling cross-tab/session credential theft; users are advised to patch immediately and be cautious about deployment given ongoing security concerns.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Security vendors and community urge users to patch OpenClaw
Following disclosure, security coverage from multiple sources warned that malicious websites could steal OpenClaw session credentials and lead to full system compromise. Users were advised to upgrade to version 2026.1.29, rotate tokens and secrets, and audit for suspicious WebSocket activity.
Technical details published for CVE-2026-25253 one-click RCE chain
Public reporting described how OpenClaw's Control UI trusted a gatewayUrl parameter, leaked an auth token over WebSocket, and allowed cross-site WebSocket hijacking because the server did not validate the Origin header. The disclosed attack chain showed how attackers could disable approvals, force host execution, and run arbitrary commands.
OpenClaw releases version 2026.1.29 to fix CVE-2026-25253
OpenClaw maintainer Peter Steinberger disclosed that the issue was fixed in OpenClaw version 2026.1.29, released on January 30, 2026. The patch addressed the flaw later tracked as CVE-2026-25253 affecting versions prior to 2026.1.29.
Researcher reports OpenClaw RCE flaw to maintainers
Security researcher Mav Levin of depthfirst reported a high-severity OpenClaw vulnerability that could lead to one-click remote code execution through authentication token exfiltration and WebSocket abuse.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
OpenClaw RCE vulnerability: CVE-2026-25253
runzero.com
Open sourceOpenClaw (aka Clawdbot) gives malicious websites access to session cookies : r/netsec
reddit.com
Open sourceOpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
thehackernews.com
Open sourceCVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration
socradar.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


