1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks
ID: 5ded3145-8fc1-5daa-9463-8b0a4b6d4dd0
STIX ID: report--5ded3145-8fc1-5daa-9463-8b0a4b6d4dd0
Feed Name: cybersecurityNews.com
Threat Score
**Executive Summary:** A critical (CVSS ~9.8) one-click RCE in the OpenClaw AI assistant allows an attacker-hosted webpage to set a malicious gatewayUrl, cause the client to auto-connect and leak auth tokens via Cross-Site WebSocket Hijacking (CSWSH), disable safety checks and invoke arbitrary host commands; OpenClaw has released a fix (upgrade to v2026.1.24-1 or later), and users should rotate tokens, audit logs, and apply network restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
