dotsagent.io
Language:English
CVE-2026-25253

OpenClaw Control UI leaked gateway tokens for one-click RCE

OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.

What happened

The OpenClaw Control UI trusted a gatewayUrl query parameter in its address. A crafted link could make the UI hand the gateway token to an attacker, who could then use the gateway to run commands. This worked even when the gateway listened only on loopback.

Mav Levin of depthfirst found the issue. It affects versions before 2026.1.29, was fixed on 30 January 2026 and was published on 31 January as CVE-2026-25253 (GHSA-g8p2-7wf7-98mq), with CVSS 8.8 and CWE-669.

Why it worked

Binding to loopback keeps strangers from reaching the gateway directly, but the user's own browser is already inside. A UI that holds the token and trusts parameters from a URL turns one click on a link into full control of the gateway.

What to do

  • Update OpenClaw to 2026.1.29 or later.
  • Rotate the gateway token after updating.
  • Don't open Control UI links that arrive in messages or on untrusted pages.
  • Run openclaw security audit --deep after every upgrade.

Keep control planes off the internetSandbox code and tool execution

Work through the security checklist →

Sources

  1. github.com/advisories/ghsa-g8p2-7wf7-98mq
  2. nvd.nist.gov/vuln/detail/CVE-2026-25253

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026