Last seen February 3, 2026

OpenClaw Cross-Site WebSocket Hijacking Vulnerability

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Technical Severity
Medium severity
Lifecycle Status

STABLE

What Happened

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Why This Matters

Publisher reporting describes a security event affecting One. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether One is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Feb 03, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: DEMONSTRATED

Primary entities:

OpenClawRemote Code ExecutionClick Remote CodeExecutionMalicious LinkOne

Authoritative Intelligence

CVE CVE-2026-25253 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Feb 02, 2026 05:30

    BugSkan first recorded this incident.

  • OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News
    Feb 02, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek
    Feb 03, 2026 05:30

    securityweek.com ยท Vulnerability

  • Latest observed development
    Feb 03, 2026 05:30

    Most recent source or update associated with this incident.

Sources

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News

thehackernews.com ยท Feb 02, 2026 05:30

A high-severity vulnerability, tracked as CVE-2026-25253, in OpenClaw allows one-click remote code execution (RCE) via a crafted malicious link. This exploit leverages a cross-site WebSocket hijacking flaw to exfiltrate authentication tokens, enabling an attacker to bypass authentication, disable security features, and execute arbitrary commands on the underlying host system.

Open publisher source
Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek

securityweek.com ยท Feb 03, 2026 05:30

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence