BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

OpenClaw AI Assistant Patched for Critical 1-Click RCE Flaw

OpenClaw AI Assistant vulnerability allows one-click remote code execution and host takeover.

  • A critical flaw in the popular AI assistant OpenClaw allows attackers to execute remote code via a single malicious link.
  • The vulnerability, patched on January 30, 2026, enabled complete system compromise by exfiltrating authentication tokens.
  • With over 149,000 GitHub stars, the locally-run software was vulnerable even when configured to listen only on localhost.
  • The one-click exploit chain could bypass critical safety sandboxes to run commands directly on a victim’s host machine.

A severe security vulnerability in the widely-used AI assistant OpenClaw was patched on January 30, 2026, allowing remote code execution through a crafted link. The flaw, tracked as CVE-2026-25253 with a high CVSS score of 8.8, could lead to full gateway compromise.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to an advisory by creator Peter Steinberger, the Control UI auto-connected using an untrusted query parameter. Consequently, clicking a malicious link could send a gateway token to an attacker-controlled server.

Discovered by Mav Levin of depthfirst, the exploit chain achieved RCE milliseconds after visiting a webpage. Levin detailed how the attack bypassed localhost restrictions via cross-site WebSocket hijacking.

The attacker could then disable user confirmations and escape the safety container. “This forces the agent to run commands directly on the host machine, not inside a Docker container,” Levin said.

Steinberger noted the vulnerability impacted any deployment where a user was authenticated. Meanwhile, the open-source project, which promises user data sovereignty, had gained rapid popularity since its November 2025 release.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump-Backed WLFI Offers Teams Access to Big Stakers

World Liberty Financial, a DeFi project backed by Donald Trump, approved a measure allowing...

Bitcoin Nears $74K, $1B Liquidations Loom

Bitcoin traded near $74,000 in Monday's session, posting a 24-hour gain of roughly 2.5%.More...

Andreas Antonopoulos Ends New Bitcoin Content Due to Migraines

Bitcoin educator Andreas Antonopoulos has announced "no more livestream Q&A or producing any new...

Bitcoin Hits $74.6K High, Yet Traders Remain Skeptical

Bitcoin (BTC) surged to approximately $74,600 at Monday’s Wall Street open, reaching a new...

Bitcoin Nears $73K: Veteran Says Worst May Be Over.

Bitcoin's price surged to $73,000 at press time, gaining momentum after a period of...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading