CVE-2026-25593Disclosure(openclaw / openclaw)

MEDIUMCVSS 8.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability is fixed in 2026.1.20.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-06: 1Mentions · 2026-02-14: 1Mentions · 2026-02-19: 2Mentions · 2026-03-02: 1Active Exploitation · 2026-02-19: 1Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-02: 102-0602-1402-1903-02
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
Active Exploitation
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-141
Patch1
2026-02-192
Active Exploitation1Disclosure1
2026-03-021
Disclosure1
Full discourse5 posts
  • Coyote Security Scanner@CoyoteSecure
    Patch

    Just pushed v1.5 of Coyote, this was a big update, see details below: - Added scans for all five OpenClaw CVEs in openclaw .py: CVE-2026-25253 CVE-2026-24763 CVE-2026-25157 CVE-2026-25475 CVE-2026-25593 These include version-threshold detection plus config-risk indicators, and are now part of secure-openclaw output. - Updated version handling in OpenClaw report output in output .py so “outdated” uses the latest tracked OpenClaw fix level (2026.1.30). - Bumped Coyote version to 1.4.0 in:__init__.py README .md (displayed version text) - Updated OpenClaw command/help text in:__main__.py - Updated README OpenClaw section in:README .md to document all five CVEs, updated checks table, and refreshed example output. - Created the new doc: OpenClawCVEs .md with all OpenClaw CVEs Coyote scans for, fixed versions, and scan logic. - Added tests in: test_openclaw_security.py

    Post summary

    The post announces a new release of Coyote v1.5, adding detection scans for five OpenClaw CVEs and documenting their fixed versions, indicating a patch release.

    43090369
    214 followersView on X
  • Henry@henry_gg08
    Active Exploitation

    🚨 135,000+ OpenClaw instances are exposed right now. CVE-2026-25253 and CVE-2026-25593 are being actively exploited. Here's how to check if you're vulnerable (30 sec): 🧵

    Post summary

    135,000+ OpenClaw instances are exposed and the CVEs CVE-2026-25253 and CVE-2026-25593 are claimed to be actively exploited.

    1000041
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25593 OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set … https://www.cve.org/CVERecord?id=CVE-2026-25593

    Post summary

    OpenClaw’s Gateway WebSocket API allows an unauthenticated local client to modify configuration via config.apply before version 2026.1.20, exposing a local privilege escalation vulnerability.

    00010201
    56.5K followersView on X
  • AIContextWindow@AIContextWindow
    Disclosure

    OpenClaw vulnerability: "ClawJacked" flaw allows malicious websites to hijack local OpenClaw AI agents via WebSocket. The core system vulnerability (CVE-2026-25593, etc.) affects all installations. Source: https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html

    Post summary

    A new CVE-2026-25593 vulnerability in OpenClaw AI agents allows malicious websites to hijack agents via WebSocket, affecting all installations.

    0000043
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25593 OpenClaw Gateway WebSocket API Unauthenticated Command Injection Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25593

    Post summary

    A new unauthenticated command injection vulnerability (CVE-2026-25593) in OpenClaw Gateway WebSocket API has been disclosed.

    0000063
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more