VYPR
High severity8.8OSV Advisory· Published Feb 1, 2026· Updated Jun 17, 2026

CVE-2026-25253

CVE-2026-25253

Description

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
clawdbotnpm
< 2026.1.292026.1.29

Affected products

3
  • OpenClaw/OpenclawOSV2 versions
    v0.1.0, v0.1.1, v0.1.2, …+ 1 more
    • (no CPE)range: v0.1.0, v0.1.1, v0.1.2, …
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: <2026.1.29
  • ghsa-coords
    Range: < 2026.1.29

Patches

Vulnerability mechanics

References

7

News mentions

5