1. Front page
  2. Incidents
  3. CVE-2026-25253: a web page that hijacks OpenClaw
Incident log · Security flaw

CVE-2026-25253: a web page that hijacks OpenClaw

Through cross-site WebSocket hijacking, a hostile web page could lift an OpenClaw gateway token and seize the instance, even when it listened on localhost alone.

At the end of January, Conscia described CVE-2026-25253, a flaw through which a malicious web page could hand an attacker control of an OpenClaw instance. The page used cross-site WebSocket hijacking to lift the gateway token, and with the token the attacker could take the agent over.

The bug undercut a comfortable assumption: that a gateway listening only on localhost is out of reach. The attack travelled through the owner's own browser, on the same machine, so the loopback boundary offered no protection. It was the one-click remote-code-execution problem that marked OpenClaw's early releases.

Version 2026.1.29 patched the flaw, together with two command-injection bugs. It was the first of several serious OpenClaw findings this year, followed by the exposed gateways in February and the Claw Chain in April.

Who was affected

OpenClaw users on versions before 2026.1.29

The lesson: Running an agent on your own hardware is no guarantee of safety. Leave automatic updates switched on, and guard the gateway token as closely as a password.

Sources