OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住关键点。 文章主要讲的是OpenClaw这个开源AI助手的一个高危安全漏洞,CVE编号是2026-25253,CVSS评分8.8。这个漏洞允许远程代码执行(RCE),通过恶意链接触发。攻击者可以窃取令牌,控制用户的网关,修改配置甚至执行特权操作。 接下来,我需要提取这些关键信息:OpenClaw是什么?它是一个本地运行的AI助手。漏洞的严重性?高危。影响范围?用户访问恶意链接后会被攻击。修复情况?已经发布了补丁版本2026.1.29。 然后,我要把这些信息浓缩到100字以内,确保语言简洁明了。不需要使用“文章总结”这样的开头,直接描述内容即可。 可能的结构是:先介绍OpenClaw和漏洞的基本情况,然后说明漏洞的影响和修复措施。这样既全面又简洁。 最后检查一下字数是否符合要求,并确保信息准确无误。 </think> OpenClaw(原名Clawdbot和Moltbot)被披露存在一个高危安全漏洞(CVE-2026-25253),可导致远程代码执行(RCE)。攻击者通过恶意链接或网站窃取用户令牌,控制用户的本地网关并执行任意操作。该漏洞已通过版本2026.1.29修复。 2026-2-2 16:28:0 Author: thehackernews.com(查看原文) 阅读量:1 收藏

Vulnerability / Artificial Intelligence

A high-severity security flaw has been disclosed in OpenClaw (formerly referred to as Clawdbot and Moltbot) that could allow remote code execution (RCE) through a crafted malicious link.

The issue, which is tracked as CVE-2026-25253 (CVSS score: 8.8), has been addressed in version 2026.1.29 released on January 30, 2026. It has been described as a token exfiltration vulnerability that leads to full gateway compromise.

"The Control UI trusts gatewayUrl from the query string without validation and auto-connects on load, sending the stored gateway token in the WebSocket connect payload," OpenClaw's creator and maintainer Peter Steinberger said in an advisory.

Cybersecurity

"Clicking a crafted link or visiting a malicious site can send the token to an attacker-controlled server. The attacker can then connect to the victim's local gateway, modify config (sandbox, tool policies), and invoke privileged actions, achieving 1-click RCE."

OpenClaw is an open-source autonomous artificial intelligence (AI) personal assistant that runs locally on user devices and integrates with a wide range of messaging platforms. Although initially released in November 2025, the project has gained rapid popularity in recent weeks, with its GitHub repository crossing 149,000 stars as of writing.

"OpenClaw is an open agent platform that runs on your machine and works from the chat apps you already use," Steinberger said. "Unlike SaaS assistants where your data lives on someone else's servers, OpenClaw runs where you choose – laptop, homelab, or VPS. Your infrastructure. Your keys. Your data."

Mav Levin, founding security researcher at depthfirst who is credited with discovering the shortcoming, said it can be exploited to create a one-click RCE exploit chain that takes only milliseconds after a victim visits a single malicious web page.

The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw's server doesn't validate the WebSocket origin header. This causes the server to accept requests from any website, effectively getting around localhost network restrictions.

A malicious web page can take advantage of the issue to execute client-side JavaScript on the victim's browser that can retrieve an authentication token, establish a WebSocket connection to the server, and use the stolen token to bypass authentication and log in to the victim's OpenClaw instance.

To make matters worse, by leveraging the token's privileged operator.admin and operator.approvals scopes, the attacker can use the API to disable user confirmation by setting "exec.approvals.set" to "off" and escape the container used to run shell tools by setting "tools.exec.host" to "gateway."

Cybersecurity

"This forces the agent to run commands directly on the host machine, not inside a Docker container," Levin said. "Finally, to achieve arbitrary command execution, the attacker JavaScript executes a node.invoke request."

When asked whether OpenClaw's use of the API to manage the safety features constitutes an architectural limitation, Levin told The Hacker News in an emailed response that, "I would say the problem is those defenses (sandbox and safety guardrails) were designed to contain malicious actions of an LLM, as a result of prompt injection, for example. And users might think these defenses would protect from this vulnerability (or limit the blast radius), but they don't."

Steinberger noted in the advisory that "the vulnerability is exploitable even on instances configured to listen on loopback only, since the victim's browser initiates the outbound connection."

"It impacts any Moltbot deployment where a user has authenticated to the Control UI. The attacker gains operator-level access to the gateway API, enabling arbitrary config changes and code execution on the gateway host. The attack works even when the gateway binds to loopback because the victim's browser acts as the bridge."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html
如有侵权请联系:admin#unsafe.sh