Last seen February 3, 2026

OpenClaw Cross-Site WebSocket Hijacking Vulnerability

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Technical Severity
Medium severity
Lifecycle Status

STABLE

What Happened

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Why This Matters

Publisher reporting describes a security event affecting One. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether One is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Feb 03, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: DEMONSTRATED

Primary entities:

OpenClawRemote Code ExecutionClick Remote CodeExecutionMalicious LinkOne

Authoritative Intelligence

CVE CVE-2026-25253 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

CVE-2026-25253: 6 public repository references found.

ethiack/moltbot-1click-rce

Possible public PoC reference

Clawdbot/Moltbot/OpenClaw One-click RCE PoC ๐Ÿฆž (CVE-2026-25253)

92 stars ยท Python

Open repository
FrigateCaptain/openclaw_vulnerabilities_and_solutions

Security advisory / research reference

> OpenClaw security audit and hardened deployment guide โ€” known vulnerabilities (CVE-2026-25253, malicious skills, credential leakage), architectural mitigations, and a step-by-step VPS deployment plan

2 stars

Open repository
adibirzu/openclaw-security-monitor

Security advisory / research reference

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

48 stars ยท Shell

Open repository
al4n4n/CVE-2026-25253-research

Public GitHub reference

GitHub repository for an AI tooling project

7 stars ยท HTML

Open repository
EQSTLab/CVE-2026-25253

Public GitHub reference

OpenClaw Authentication Token Exfiltration

2 stars ยท HTML

Open repository
KajzingerAkos/CVE-2026-25253

Public GitHub reference

CVE-2026-25253: One-Click RCE in OpenClaw via Auth Token Theft

1 stars ยท HTML

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Feb 02, 2026 05:30

    BugSkan first recorded this incident.

  • OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News
    Feb 02, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek
    Feb 03, 2026 05:30

    securityweek.com ยท Vulnerability

  • Latest observed development
    Feb 03, 2026 05:30

    Most recent source or update associated with this incident.

Sources

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News

thehackernews.com ยท Feb 02, 2026 05:30

A high-severity vulnerability, tracked as CVE-2026-25253, in OpenClaw allows one-click remote code execution (RCE) via a crafted malicious link. This exploit leverages a cross-site WebSocket hijacking flaw to exfiltrate authentication tokens, enabling an attacker to bypass authentication, disable security features, and execute arbitrary commands on the underlying host system.

Open publisher source
Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek

securityweek.com ยท Feb 03, 2026 05:30

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence