A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.
Why This Matters
Publisher reporting describes a security event affecting One. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether One is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2026-25253
Affected