CVE-2026-25253: Openclaw
High severity, CVSS 8.8. EPSS: 24.4% chance of exploitation in the next 30 days.
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
Affected products
- Openclaw Openclaw: before 2026.1.29 (fixed in 2026.1.29)
Published 2026-02-01. Last modified 2026-06-17.