logo

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

ID: 44ea92c9-eee1-57ea-a7ee-119d0b508238

STIX ID: report--44ea92c9-eee1-57ea-a7ee-119d0b508238

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A high-severity vulnerability (CVE-2026-25253, CVSS 8.8) in OpenClaw's Control UI lets an attacker exfiltrate stored gateway tokens via a crafted link and achieve one-click remote code execution by abusing missing WebSocket origin validation and gateway API controls; the flaw can be exploited even when the gateway is bound to loopback and was fixed in version 2026.1.29 (released Jan 30, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.