OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
References
Configurations
No configuration.
History
03 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys - |
Information
Published : 2026-02-01 23:15
Updated : 2026-02-03 16:44
NVD link : CVE-2026-25253
Mitre link : CVE-2026-25253
CVE.ORG link : CVE-2026-25253
JSON object : View
Products Affected
No product.
CWE
CWE-669
Incorrect Resource Transfer Between Spheres
