BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

OpenClaw AI Assistant Patched for Critical 1-Click RCE Flaw

OpenClaw AI Assistant vulnerability allows one-click remote code execution and host takeover.

  • A critical flaw in the popular AI assistant OpenClaw allows attackers to execute remote code via a single malicious link.
  • The vulnerability, patched on January 30, 2026, enabled complete system compromise by exfiltrating authentication tokens.
  • With over 149,000 GitHub stars, the locally-run software was vulnerable even when configured to listen only on localhost.
  • The one-click exploit chain could bypass critical safety sandboxes to run commands directly on a victim’s host machine.

A severe security vulnerability in the widely-used AI assistant OpenClaw was patched on January 30, 2026, allowing remote code execution through a crafted link. The flaw, tracked as CVE-2026-25253 with a high CVSS score of 8.8, could lead to full gateway compromise.

- Advertisement -

According to an advisory by creator Peter Steinberger, the Control UI auto-connected using an untrusted query parameter. Consequently, clicking a malicious link could send a gateway token to an attacker-controlled server.

Discovered by Mav Levin of depthfirst, the exploit chain achieved RCE milliseconds after visiting a webpage. Levin detailed how the attack bypassed localhost restrictions via cross-site WebSocket hijacking.

The attacker could then disable user confirmations and escape the safety container. “This forces the agent to run commands directly on the host machine, not inside a Docker container,” Levin said.

Steinberger noted the vulnerability impacted any deployment where a user was authenticated. Meanwhile, the open-source project, which promises user data sovereignty, had gained rapid popularity since its November 2025 release.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor Signals Strategy’s Next Bitcoin Purchase Amid Rally

MicroStrategy, led by Michael Saylor, recently purchased 34,164 Bitcoin for over $2.5 billion.The company's...

Indonesia to Start Buying Russian Oil in April

New BRICS member Indonesia plans to begin importing oil from Russia as early as...

Coachella, Google DeepMind Test AI “World Models” at 2026 Fest

Coachella built three AI prototypes with Google DeepMind during its 2026 festival to transform...

Ether ETFs See 10-Day Inflow Streak Amid Fund Unstaking

US spot Ethereum ETFs recorded a 10-day inflow streak last week, signaling persistent institutional...

Nvidia Stock Eyes $380 as Analysts, Dalio Bet Big on AI Boom

Analysts have set a consensus NVIDIA stock price target of $268.80, with high estimates...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading