CVE-2026-25253: Openclaw

High severity, CVSS 8.8. EPSS: 24.4% chance of exploitation in the next 30 days.

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Affected products

  • Openclaw Openclaw: before 2026.1.29 (fixed in 2026.1.29)

Published 2026-02-01. Last modified 2026-06-17.