---
title: "CVE-2026-25253 in OpenClaw: Case File and Patch · AgentDots"
description: "How CVE-2026-25253 let a hostile web page steal an OpenClaw gateway token by cross-site WebSocket hijacking, even on localhost, and why 2026.1.29 matters."
url: https://agentdots.org/incidents/openclaw-cve-2026-25253/
lang: en
---

Incident log · Security flaw

# CVE-2026-25253: a web page that hijacks OpenClaw

Through cross-site WebSocket hijacking, a hostile web page could lift an OpenClaw gateway token and seize the instance, even when it listened on localhost alone.

January 30, 2026 HighOpenClaw

At the end of January, Conscia described CVE-2026-25253, a flaw through which a malicious web page could hand an attacker control of an OpenClaw instance. The page used cross-site WebSocket hijacking to lift the gateway token, and with the token the attacker could take the agent over.

The bug undercut a comfortable assumption: that a gateway listening only on localhost is out of reach. The attack travelled through the owner's own browser, on the same machine, so the loopback boundary offered no protection. It was the one-click remote-code-execution problem that marked OpenClaw's early releases.

Version 2026.1.29 patched the flaw, together with two command-injection bugs. It was the first of several serious OpenClaw findings this year, followed by the exposed gateways in February and the Claw Chain in April.

## Who was affected

OpenClaw users on versions before 2026.1.29

The lesson: Running an agent on your own hardware is no guarantee of safety. Leave automatic updates switched on, and guard the gateway token as closely as a password.

**Sources**

- [Conscia](https://conscia.com/blog/the-openclaw-security-crisis/)

[OpenClaw](https://agentdots.org/agents/openclaw/)

Safety

[Work through the 18-point checklist →](https://agentdots.org/safety/checklist/)

## Incident log

September 28, 2026
[GPT-6.1 Astra withdrawn after failing its own tests](https://agentdots.org/incidents/astra-launch-halted/)

September 28, 2026
[Muse tells a stranger where its seller lives](https://agentdots.org/incidents/muse-shared-home-address/)

September 25, 2026
[Research agents post 53 user images to public hosts](https://agentdots.org/incidents/research-agents-posted-images/)

September 25, 2026
[Flaw opened a possible route into Muse machines](https://agentdots.org/incidents/muse-vm-vulnerability/)

September 20, 2026
[Amazon closes its store to Meta's Muse](https://agentdots.org/incidents/amazon-blocks-muse/)
