CVE-2026-25253
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
- Affected products
- Openclaw
- Openclaw
- < 2026.1.29
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 23.6% (98th percentile)
- Weakness
- CWE-669
- NVD status
- Analyzed
- Published
- 2026-02-01
CVE-2026-25253 at NVD
9 known exploits for CVE-2026-25253
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-25253
openclaw-security-monitor
leash-poc
Gideon
Exploit for Incorrect Resource Transfer Between Spheres in Openclaw
Exploit for Incorrect Resource Transfer Between Spheres in Openclaw
Exploit for Incorrect Resource Transfer Between Spheres in Openclaw
Exploit for CVE-2026-25253
Exploit for CVE-2026-25253