A serious security flaw has been discovered in OpenClaw (formerly known as Clawdbot and Moltbot), which could allow remote code execution (RCE) via a malicious link. The issue, tracked as CVE-2026-25253 (CVSS score: 8.8), has been resolved in version 2026.1.29 released on January 30, 2026. It has been described as a token extraction vulnerability leading to a full portal compromise.
See also: SmarterMail fixes critical RCE vulnerability

“Control UI trusts the gatewayUrl from the query string without validation and connects automatically on load, sending the stored gateway token in the WebSocket connection payload,” said OpenClaw creator and maintainer Peter Steinbergerin an advisory.
“Clicking on a crafted link or visiting a malicious website can send the token to a server controlled by the attacker. The attacker can then connect to the victim’s local portal, modify the configuration (sandbox, tool policies) and perform privileged actions, achieving a one-click RCE.” OpenClaw is an open-source autonomous artificial intelligence (AI) personal assistant that runs locally on users’ devices and integrates with a wide range of messaging platforms.
Although it was originally released in November 2025, the project has rapidly gained popularity in recent weeks, with its GitHub repository currently exceeding 149,000 stars
Mav Levin, a founding security researcher at depthfirst who is credited with discovering the vulnerability, said it can be exploited to create a one-click RCE exploit chain that takes only milliseconds after the victim visits a malicious website. The problem is that clicking on the link to that website is enough to trigger a cross-site WebSocket hijacking because the OpenClaw server does not validate the WebSocket.
See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk

This causes the server to accept requests from any website, effectively bypassing the localhost. A malicious website can exploit the issue to execute client-side JavaScript in the victim's browser that can retrieve an authentication token, establish a WebSocket connection to the server, and use the stolen token to bypass authentication and log in to the victim's OpenClaw instance.
To make matters worse, by exploiting the privileged operator.admin and operator.approvals of the token, the attacker can use the API to disable user confirmation by setting “exec.approvals.set” to “off” and escape the container used to run shell tools by setting “tools.exec.host” to “gateway.” “This forces the agent to execute commands directly on the host machine, not inside a Docker container,” Levin said.
When asked if OpenClaw's use of the API to manage security features is an architectural limitation, Levin told The Hacker News in an email response that, “I would say the problem is that these defenses (sandboxes and security guardrails) were designed to contain malicious actions of an LLM, as a result of prompt injection, for example. And users may think that these defenses will protect them from this vulnerability (or limit the blast radius), but they don't.”
See also: Two serious vulnerabilities in n8n allow RCE

Steinberger noted in the advisory that “the vulnerability is exploitable even in cases configured to listen only on loopback, as the victim’s browser initiates the outbound connection.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
