CVE-2026-25253OpenClaw Control UI leaked gateway tokens for one-click RCE
OpenClaw's Control UI trusted a gatewayUrl query parameter, leaking the gateway token and enabling one-click RCE, even on loopback-only installs. CVSS 8.8.
What happened
The OpenClaw Control UI trusted a gatewayUrl query parameter in its address. A crafted link could make the UI hand the gateway token to an attacker, who could then use the gateway to run commands. This worked even when the gateway listened only on loopback.
Mav Levin of depthfirst found the issue. It affects versions before 2026.1.29, was fixed on 30 January 2026 and was published on 31 January as CVE-2026-25253 (GHSA-g8p2-7wf7-98mq), with CVSS 8.8 and CWE-669.
Why it worked
Binding to loopback keeps strangers from reaching the gateway directly, but the user's own browser is already inside. A UI that holds the token and trusts parameters from a URL turns one click on a link into full control of the gateway.
What to do
- Update OpenClaw to 2026.1.29 or later.
- Rotate the gateway token after updating.
- Don't open Control UI links that arrive in messages or on untrusted pages.
- Run openclaw security audit --deep after every upgrade.
Keep control planes off the internetSandbox code and tool execution
OpenClaw gateways exposed to the internet at scale
postmark-mcp: malicious MCP server copied every email
Work through the security checklist →