Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant
Critical token-exfiltration vulnerability CVE-2026-25253 allowed attackers to hijack OpenClaw instances via malicious websites; patched in version 2026.1.29.
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
A token-exfiltration vulnerability in OpenClaw allowed one-click remote code execution by trusting an unvalidated gatewayUrl and auto-sending stored gateway tokens.