logo

1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks

ID: 5ded3145-8fc1-5daa-9463-8b0a4b6d4dd0

STIX ID: report--5ded3145-8fc1-5daa-9463-8b0a4b6d4dd0

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-05-05

Author: Abinaya

...
...

**Executive Summary:** A critical (CVSS ~9.8) one-click RCE in the OpenClaw AI assistant allows an attacker-hosted webpage to set a malicious gatewayUrl, cause the client to auto-connect and leak auth tokens via Cross-Site WebSocket Hijacking (CSWSH), disable safety checks and invoke arbitrary host commands; OpenClaw has released a fix (upgrade to v2026.1.24-1 or later), and users should rotate tokens, audit logs, and apply network restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.