OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
PoC: moltbot-1click-rce
Clawdbot/Moltbot/OpenClaw One-click RCE PoC π¦ (CVE-2026-25253)
PoC: red-team-blue-team-agent-fabric
470 security tests for AI agent systems β MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, CVE-2026-25253 reproduction. v4.4.2
PoC: CVE-2026-25253
OpenClaw Authentication Token Exfiltration
PoC: openclaw-hardening-check
Offline, read-only hardening check for a self-hosted OpenClaw install β gateway exposure, auth, CVE-2026-25253. Never prints secrets, makes no network calls.
PoC: agentbox
Open-source sandboxed runtime for AI agents β gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.
PoC: CVE-2026-25253
CVE-2026-25253: One-Click RCE in OpenClaw via Auth Token Theft
PoC: openclaw-1click-rce-env
THIS FORK IS FOR CVE-2026-25253 TARGET DRONE DEPLOYMENT ONLY, DON'T USE IT FOR OTHER PURPOSE
PoC: openclaw_vulnerabilities_and_solutions
> OpenClaw security audit and hardened deployment guide β known vulnerabilities (CVE-2026-25253, malicious skills, credential leakage), architectural mitigations, and a step-by-step VPS deployment plan
PoC: moatbot-security
Security-hardened AI agent platform addressing OpenClaw/Moltbot vulnerabilities (CVE-2026-25253)
PoC: openclaw-vuln-report
OpenClaw CVE-2026-25253 ζΌζ΄εζδΈζη
PoC: openclaw-security-monitor
Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.
PoC: start-here
Michael Saleme β Decision Governance for Autonomous Agents. 5 DOIs, 3 NIST submissions, CVE-2026-25253, 358 security tests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free