一键 RCE 窃取你的 OpenClaw 数据与密钥(CVE-2026-25253)
depthfirst.com | 漏洞 | 高危 | CVE-2026-25253 | #ai-security | #rce | #exploit-chain | #ai-assistant | #openclaw | #cve-2026-25253 | #token-exfiltration
摘要
对开源 AI 助手 OpenClaw 的一键 RCE 组合利用剖析:gatewayUrl 设置逻辑缺陷与 WebSocket 跳板相结合,仅需访问一次恶意网页即可泄露认证令牌、绕过安全控制并执行任意命令(CVE-2026-25253)。
- CVSS
- 8.8
- 发布时间
- 收录时间
Skip to content