Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

1-Click RCE To Steal Your OpenClaw Data and Keys (CVE-2026-25253)

Summary

A 1-click RCE chain against OpenClaw, the open-source AI assistant: a gatewayUrl settings flaw plus a WebSocket pivot turn one malicious page visit into token theft and command execution.
CVSS
8.8
Published
Collected

original ↗

Related coverage

back