VYPR
High severityOSV Advisory· Published Feb 1, 2026· Updated Feb 3, 2026

CVE-2026-25253

CVE-2026-25253

Description

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
clawdbotnpm
< 2026.1.292026.1.29

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.