---
title: "OpenClaw Control UI leaked gateway tokens for one-click RCE · DotsAgent"
description: "OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8."
url: https://dotsagent.io/security/incidents/2026-01-openclaw-control-ui-rce
---

January 30, 2026

CVE-2026-25253

# OpenClaw Control UI leaked gateway tokens for one-click RCE

OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.

## What happened

The OpenClaw Control UI trusted a gatewayUrl query parameter in its address. A crafted link could make the UI hand the gateway token to an attacker, who could then use the gateway to run commands. This worked even when the gateway listened only on loopback.

Mav Levin of depthfirst found the issue. It affects versions before 2026.1.29, was fixed on 30 January 2026 and was published on 31 January as CVE-2026-25253 (GHSA-g8p2-7wf7-98mq), with CVSS 8.8 and CWE-669.

## Why it worked

Binding to loopback keeps strangers from reaching the gateway directly, but the user's own browser is already inside. A UI that holds the token and trusts parameters from a URL turns one click on a link into full control of the gateway.

## What to do

- Update OpenClaw to 2026.1.29 or later.
- Rotate the gateway token after updating.
- Don't open Control UI links that arrive in messages or on untrusted pages.
- Run openclaw security audit --deep after every upgrade.

[Keep control planes off the internet](https://dotsagent.io/security#noPublicControlPlane)[Sandbox code and tool execution](https://dotsagent.io/security#sandboxing)

- [OpenClaw gateways exposed to the internet at scale](https://dotsagent.io/security/incidents/2026-openclaw-gateways-exposed)

- [postmark-mcp: malicious MCP server copied every email](https://dotsagent.io/security/incidents/2025-09-postmark-mcp-backdoor)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [github.com](https://github.com/advisories/ghsa-g8p2-7wf7-98mq)/advisories/ghsa-g8p2-7wf7-98mq
2. [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25253)/vuln/detail/CVE-2026-25253

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
