At the end of January, Conscia described CVE-2026-25253, a flaw through which a malicious web page could hand an attacker control of an OpenClaw instance. The page used cross-site WebSocket hijacking to lift the gateway token, and with the token the attacker could take the agent over.
The bug undercut a comfortable assumption: that a gateway listening only on localhost is out of reach. The attack travelled through the owner's own browser, on the same machine, so the loopback boundary offered no protection. It was the one-click remote-code-execution problem that marked OpenClaw's early releases.
Version 2026.1.29 patched the flaw, together with two command-injection bugs. It was the first of several serious OpenClaw findings this year, followed by the exposed gateways in February and the Claw Chain in April.
Who was affected
OpenClaw users on versions before 2026.1.29
The lesson: Running an agent on your own hardware is no guarantee of safety. Leave automatic updates switched on, and guard the gateway token as closely as a password.