BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

OpenClaw AI Assistant Patched for Critical 1-Click RCE Flaw

OpenClaw AI Assistant vulnerability allows one-click remote code execution and host takeover.

  • A critical flaw in the popular AI assistant OpenClaw allows attackers to execute remote code via a single malicious link.
  • The vulnerability, patched on January 30, 2026, enabled complete system compromise by exfiltrating authentication tokens.
  • With over 149,000 GitHub stars, the locally-run software was vulnerable even when configured to listen only on localhost.
  • The one-click exploit chain could bypass critical safety sandboxes to run commands directly on a victim’s host machine.

A severe security vulnerability in the widely-used AI assistant OpenClaw was patched on January 30, 2026, allowing remote code execution through a crafted link. The flaw, tracked as CVE-2026-25253 with a high CVSS score of 8.8, could lead to full gateway compromise.

- Advertisement -

According to an advisory by creator Peter Steinberger, the Control UI auto-connected using an untrusted query parameter. Consequently, clicking a malicious link could send a gateway token to an attacker-controlled server.

Discovered by Mav Levin of depthfirst, the exploit chain achieved RCE milliseconds after visiting a webpage. Levin detailed how the attack bypassed localhost restrictions via cross-site WebSocket hijacking.

The attacker could then disable user confirmations and escape the safety container. “This forces the agent to run commands directly on the host machine, not inside a Docker container,” Levin said.

Steinberger noted the vulnerability impacted any deployment where a user was authenticated. Meanwhile, the open-source project, which promises user data sovereignty, had gained rapid popularity since its November 2025 release.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Smart TVs Co-opted Into AI Data-Scraping Network

A security researcher has reverse-engineered how a popular data firm turns consumer devices, including...

Ether Hits 13-Month Low Amid DeFi Liquidations, Bug

Ether derivatives metrics turned heavily bearish after cascading liquidations prevented a recovery.A critical ZCash...

Zcash Plunges After Critical Four-Year-Old Bug Revealed

ZCash's price dropped sharply after disclosure of a critical, four-year-old vulnerability.The bug's full scope...

Bitcoin ETFs Bleed $4.3B in 13-Day Outflow Streak

Spot Bitcoin ETFs endured a record 13-day net outflow streak, shedding over $4.3 billion,...

Kraken Offers Tokenized SpaceX IPO Access

Kraken will offer access to the upcoming SpaceX IPO via its tokenized equities platform,...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading