CVE-2026-25253

HIGH EXPLOITED LAB

OpenClaw <2026.1.29 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-25253 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 12 public exploits from researchers including ethiack, msaleme, XiaomingX.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2026-25253, targeting a vulnerability in Moltbot. The exploit involves a Flask-based server to capture tokens and passwords, and a Playwright-based script to automate the exploitation process.

Description

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Exploits (12)

nomisec WORKING POC 72 stars
by ethiack · infoleak
https://github.com/ethiack/moltbot-1click-rce

This repository contains a proof-of-concept exploit for CVE-2026-25253, targeting a vulnerability in Moltbot. The exploit involves a Flask-based server to capture tokens and passwords, and a Playwright-based script to automate the exploitation process.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Moltbot (version not specified)
No auth needed
Prerequisites: Access to the target Moltbot instance · Network connectivity to the exploit server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 17 stars
by msaleme · poc
https://github.com/msaleme/red-team-blue-team-agent-fabric

This repository contains a functional exploit PoC for CVE-2026-25253, demonstrating MCP supply chain poisoning via nested schema fields in tool definitions. It includes test harnesses for multiple CVEs, including privilege escalation (CVE-2026-35625) and SSRF (CVE-2026-35629), with simulated and live endpoint testing capabilities.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: MCP marketplace/registry and OpenClaw agent framework
No auth needed
Prerequisites: Access to MCP marketplace/registry API or a vulnerable MCP server instance
devstral-2 · analyzed May 25, 2026 Full analysis →
github WRITEUP 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25253

This repository contains detailed documentation and deployment guides for OpenClaw, an open-source AI assistant platform, but does not include actual exploit code or technical analysis of CVE-2026-25253.

Classification
Writeup 90%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: OpenClaw
No auth needed
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec SCANNER 8 stars
by adibirzu · poc
https://github.com/adibirzu/openclaw-security-monitor

This repository is a security monitoring tool for OpenClaw deployments, designed to detect threats such as CVE-2026-25253 (WebSocket hijacking RCE), AMOS stealer, and other malicious activities. It includes a 32-point scanner, remediation scripts, and a web dashboard for real-time monitoring.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: OpenClaw (self-hosted installations)
No auth needed
Prerequisites: Access to the OpenClaw deployment environment · Bash and Node.js runtime
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by KajzingerAkos · client-side
https://github.com/KajzingerAkos/CVE-2026-25253

This repository contains a functional exploit for CVE-2026-25253, demonstrating a one-click RCE in OpenClaw via authentication token theft. The PoC includes a detailed technical writeup, attacker server code, and a step-by-step exploitation process.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenClaw (clawbot) < v2026.1.29
No auth needed
Prerequisites: Victim must be authenticated in OpenClaw · Victim must click a malicious link
devstral-2 · analyzed Apr 18, 2026 Full analysis →
nomisec SUSPICIOUS
by msaleme · poc
https://github.com/msaleme/start-here

The repository is a promotional page for a security framework and research by Michael Saleme, with no actual exploit code or technical details about CVE-2026-25253. It primarily serves as a marketing tool for services and tools.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
devstral-2 · analyzed Apr 09, 2026 Full analysis →
nomisec SUSPICIOUS
by ZhaoymOvO · poc
https://github.com/ZhaoymOvO/openclaw-1click-rce-env

The repository contains no actual exploit code for CVE-2026-25253. Instead, it provides workflow documentation for syncing a fork with upstream, which is unrelated to the CVE. The README and files focus on development processes rather than vulnerability details or exploit techniques.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Mar 24, 2026 Full analysis →
nomisec WORKING POC
by EQSTLab · client-side
https://github.com/EQSTLab/CVE-2026-25253

This is a functional exploit PoC for CVE-2026-25253, which appears to target a gateway token capture vulnerability. The exploit sets up a Flask server with WebSocket support to intercept and capture gateway tokens, likely for authentication bypass or session hijacking.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Unknown (likely a gateway or authentication service)
No auth needed
Prerequisites: Network access to the target service · Target service must be vulnerable to token capture via WebSocket
devstral-2 · analyzed Mar 09, 2026 Full analysis →
nomisec WRITEUP
by FrigateCaptain · poc
https://github.com/FrigateCaptain/openclaw_vulnerabilities_and_solutions

This repository contains sanitized documentation for deploying OpenClaw on a VPS, including architectural decisions, security requirements, and deployment plans. It does not include exploit code but provides detailed technical insights into the platform's setup and potential security considerations.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: OpenClaw
No auth needed
Prerequisites: Access to VPS · Ubuntu 24.04 LTS · OpenRouter API key
devstral-2 · analyzed Feb 22, 2026 Full analysis →
nomisec WRITEUP
by Ckokoski · poc
https://github.com/Ckokoski/moatbot-security

This repository is a security-hardened fork of OpenClaw, addressing multiple vulnerabilities including CVE-2026-25253. It provides a detailed technical analysis of the vulnerabilities, remediation strategies, and architectural improvements without including functional exploit code.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: OpenClaw (AI agent platform)
No auth needed
Prerequisites: Access to vulnerable OpenClaw instance · Network access to exposed endpoints
devstral-2 · analyzed Feb 21, 2026 Full analysis →
nomisec WORKING POC
by al4n4n · client-side
https://github.com/al4n4n/CVE-2026-25253-research

This repository contains a functional proof-of-concept exploit for CVE-2026-25253, leveraging Cross-Site WebSocket Hijacking to achieve one-click RCE on OpenClaw. The exploit involves token theft, WebSocket hijacking, and command execution via a browser-based payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenClaw (version not specified)
Auth required
Prerequisites: Node.js v18+ · Victim must have an active auth token in their browser · Victim must open the exploit URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by Joseph19820124 · poc
https://github.com/Joseph19820124/openclaw-vuln-report

This repository contains a Chinese-language writeup for CVE-2026-25253, describing a Cross-Site WebSocket Hijacking vulnerability in OpenClaw that allows one-click remote code execution. It references external sources but does not include exploit code or technical details.

Classification
Writeup 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: OpenClaw (version unspecified)
No auth needed
Prerequisites: Victim interaction (one-click)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull ollama/ollama:latest
docker pull envoyproxy/envoy:v1.31-latest
+9 more repos

Details

VulnCheck KEV 2026-02-19
CWE
CWE-669
Status published
Products (2)
npm/clawdbot 0 - 2026.1.29npm
openclaw/openclaw < 2026.1.29
Published Feb 01, 2026
Tracked Since Feb 18, 2026