Vulnerability intelligence
CVE-2026-25253
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
CVSS Score
8.8
High
EPSS — Exploit Probability
24%
Riskier than 98% of all CVEs · checked 2026-10-06
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
5 articles across 4 outlets · first covered Aug 26, 2026 · latest Aug 26, 2026
Coverage timeline
-
AI driven software surge fuels record Q2 2026 vulnerability spikesecurelist.com · Aug 26, 2026
-
OpenClaw flaw lets malicious site hijack agent CVE-2026-25253www.darkreading.com · Mar 2, 2026
-
OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debutswww.securityweek.com · Feb 19, 2026
-
Vulnerability Allows Hackers to Hijack OpenClaw AI Assistantwww.securityweek.com · Feb 3, 2026
-
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Linkthehackernews.com · Feb 2, 2026