All CVEs
Vulnerability intelligence

CVE-2026-25253

OpenClaw OpenClaw CWE-669

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

CVSS Score
8.8
High
EPSS — Exploit Probability
24%
Riskier than 98% of all CVEs · checked 2026-10-06
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

5 articles across 4 outlets · first covered Aug 26, 2026 · latest Aug 26, 2026

Coverage timeline

Related CVEs — OpenClaw