CVE-2026-25253

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
Configurations

No configuration.

History

03 Feb 2026, 16:16

Type Values Removed Values Added
References () https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys - () https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys -

Information

Published : 2026-02-01 23:15

Updated : 2026-02-03 16:44


NVD link : CVE-2026-25253

Mitre link : CVE-2026-25253

CVE.ORG link : CVE-2026-25253


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres