logo

CVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration

ID: efc0c61d-e402-502b-af19-1a6ddf5fbe48

STIX ID: report--efc0c61d-e402-502b-af19-1a6ddf5fbe48

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-02-02

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**CVE-2026-25253** is a critical logic vulnerability in OpenClaw (formerly Clawdbot/Moltbot) that permits a one‑click attack: a malicious gatewayUrl causes the application to connect to an attacker WebSocket, leak the user's authToken, enable Cross‑Site WebSocket Hijacking to reach localhost, disable prompts and container protections, and then execute arbitrary commands on the host; affected versions include releases up to v2026.1.24-1 and recommended mitigations are immediate patching, rotating tokens and connected secrets, and auditing logs and permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.