---
title: "OpenClaw Control UI 泄露 gateway token，导致一键 RCE · DotsAgent"
description: "OpenClaw 的 Control UI 信任 gatewayUrl 查询参数，导致 gateway token 泄露并可一键触发 RCE，即使安装仅绑定到 loopback 也不例外。CVSS 8.8。"
url: https://dotsagent.io/zh/security/incidents/2026-01-openclaw-control-ui-rce
---

2026年1月30日

CVE-2026-25253

# OpenClaw Control UI 泄露 gateway token，导致一键 RCE

OpenClaw 的 Control UI 信任 gatewayUrl 查询参数，导致 gateway token 泄露并可一键触发 RCE，即使安装仅绑定到 loopback 也不例外。CVSS 8.8。

## 事件经过

OpenClaw Control UI 会信任地址中的 gatewayUrl 查询参数。攻击者可以制作恶意链接，让 UI 将 gateway token 交给攻击者，之后攻击者就能通过 gateway 执行命令。即使 gateway 只监听 loopback，此攻击也能奏效。

depthfirst 的 Mav Levin 发现了该问题。受影响版本为 2026.1.29 之前的版本；该问题于 2026 年 1 月 30 日修复，并于 2026 年 1 月 31 日以 CVE-2026-25253 (GHSA-g8p2-7wf7-98mq) 发布，CVSS 为 8.8，CWE 为 669。

## 攻击奏效的原因

绑定到 loopback 可以阻止陌生人直接访问 gateway，但用户自己的浏览器已经处于其内部。若 UI 持有 token 并信任 URL 参数，点击一次链接就可能让攻击者完全控制 gateway。

## 应对措施

- 将 OpenClaw 更新到 2026.1.29 或更高版本。
- 更新后轮换 gateway token。
- 不要打开通过消息发送或来自不可信网页的 Control UI 链接。
- 每次升级后运行 openclaw security audit --deep。

[不要将控制面暴露到互联网](https://dotsagent.io/zh/security#noPublicControlPlane)[对代码和工具执行进行沙箱隔离](https://dotsagent.io/zh/security#sandboxing)

- [大量 OpenClaw 网关暴露于互联网](https://dotsagent.io/zh/security/incidents/2026-openclaw-gateways-exposed)

- [postmark-mcp：恶意 MCP 服务器暗中复制所有邮件](https://dotsagent.io/zh/security/incidents/2025-09-postmark-mcp-backdoor)

[查看安全检查清单 →](https://dotsagent.io/zh/security/checklist)

## 来源

1. [github.com](https://github.com/advisories/ghsa-g8p2-7wf7-98mq)/advisories/ghsa-g8p2-7wf7-98mq
2. [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-25253)/vuln/detail/CVE-2026-25253

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
