CVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration
ID: efc0c61d-e402-502b-af19-1a6ddf5fbe48
STIX ID: report--efc0c61d-e402-502b-af19-1a6ddf5fbe48
Feed Name: SOCRadar Blog
**CVE-2026-25253** is a critical logic vulnerability in OpenClaw (formerly Clawdbot/Moltbot) that permits a one‑click attack: a malicious gatewayUrl causes the application to connect to an attacker WebSocket, leak the user's authToken, enable Cross‑Site WebSocket Hijacking to reach localhost, disable prompts and container protections, and then execute arbitrary commands on the host; affected versions include releases up to v2026.1.24-1 and recommended mitigations are immediate patching, rotating tokens and connected secrets, and auditing logs and permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
