One Click to “God Mode”: The Critical OpenClaw Flaw That Handed Attackers Your Master Keys
ID: 44e69f30-5bdf-5268-9652-0d910b4012ad
STIX ID: report--44e69f30-5bdf-5268-9652-0d910b4012ad
Feed Name: securityonline.info
Threat Score
A critical vulnerability in the OpenClaw (formerly Moltbot/ClawdBot) UI fails to validate gateway URL query strings, causing the browser to transmit a stored gateway token in the WebSocket payload; an attacker can steal that token via a crafted link or phishing page to gain administrative control and trigger remote code execution. The flaw was responsibly disclosed and patched in v2026.1.29; instances running v2026.1.28 or earlier should be upgraded immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
