1-Click RCE To Steal Your OpenClaw Data and Keys (CVE-2026-25253)
depthfirst.com | vulnerability | High | CVE-2026-25253 | #ai-security | #rce | #exploit-chain | #ai-assistant | #openclaw | #cve-2026-25253 | #token-exfiltration
Summary
A 1-click RCE chain against OpenClaw, the open-source AI assistant: a gatewayUrl settings flaw plus a WebSocket pivot turn one malicious page visit into token theft and command execution.
- CVSS
- 8.8
- Published
- Collected
Skip to content