CVE-2026-25253
HIGH 8.8EPSS 24.0%
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 23.99% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2026-02-01
- Updated
- 2026-02-03
Proof-of-concept exploits (7)
- ethiack/moltbot-1click-rce92★ · 2026-01-27
- al4n4n/CVE-2026-25253-research7★ · 2026-02-08
- EQSTLab/CVE-2026-252532★ · 2026-05-20
- KajzingerAkos/CVE-2026-252531★ · 2026-04-18
- tonydzi/leash-poc0★ · 2026-08-26
- the-void-ia/ai-agent-security-labs0★ · 2026-04-14
- agenticdome/agenticdome-openclaw-security-ts0★ · 2026-08-31