logo

One Click to “God Mode”: The Critical OpenClaw Flaw That Handed Attackers Your Master Keys

ID: 44e69f30-5bdf-5268-9652-0d910b4012ad

STIX ID: report--44e69f30-5bdf-5268-9652-0d910b4012ad

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability in the OpenClaw (formerly Moltbot/ClawdBot) UI fails to validate gateway URL query strings, causing the browser to transmit a stored gateway token in the WebSocket payload; an attacker can steal that token via a crafted link or phishing page to gain administrative control and trigger remote code execution. The flaw was responsibly disclosed and patched in v2026.1.29; instances running v2026.1.28 or earlier should be upgraded immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.