Last seen February 3, 2026

CVE-2026-25253 Remote Code Execution Vulnerability affecting AI

Evidence indicates that the affected technology is affected by remote code execution. Reported affected versions include

Technical Severity
Medium severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that the affected technology is affected by remote code execution. Reported affected versions include

Why This Matters

The evidence matters to defenders using Click Remote Code because it could let an attacker run code in affected environments.

Recommended Action

Upgrade clawdbot to 2026.1.29 or later. Identify deployments of Click Remote Code matching the evidenced affected versions: <= 2026.1.28.

Exposure

Recommended Response
First Seen

Feb 02, 2026 05:30

Last Seen

Feb 03, 2026 05:30

Exploitation status: UNKNOWN

Affected versions: <= 2026.1.28

Primary entities:

Remote Code Execution CVE-2026-25253 clawdbot

Authoritative Intelligence

CVE CVE-2026-25253 Incident identifier
NVD CVSS 8.8 HIGH NVD
FIRST EPSS 0.080 94.3 pct
Fixed Version 2026.1.29 Provider-backed
GHSA GHSA-G8P2-7WF7-98MQ GitHub advisory alias
CWE CWE-669, CWE-668 Weakness classification

Provider evidence: NVD, GitHub Advisory, OSV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Feb 02, 2026 05:30

    BugSkan first recorded this incident.

  • OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News
    Feb 02, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek
    Feb 03, 2026 05:30

    securityweek.com ยท Vulnerability

  • Latest observed development
    Feb 03, 2026 05:30

    Most recent source or update associated with this incident.

  • Material change
    Aug 18, 2026 14:07

    severity 6.5 -> 8.0

Sources

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link - The Hacker News

thehackernews.com ยท Feb 02, 2026 05:30

A high-severity vulnerability, tracked as CVE-2026-25253, in OpenClaw allows one-click remote code execution (RCE) via a crafted malicious link. This exploit leverages a cross-site WebSocket hijacking flaw to exfiltrate authentication tokens, enabling an attacker to bypass authentication, disable security features, and execute arbitrary commands on the underlying host system.

Open publisher source
Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant - SecurityWeek

securityweek.com ยท Feb 03, 2026 05:30

A critical token exfiltration vulnerability, tracked as CVE-2026-25253, was discovered in the OpenClaw (Moltbot/Clawdbot) AI assistant. This one-click remote code execution flaw allows attackers to hijack user instances by tricking victims into visiting a malicious website to steal authentication tokens, leading to operator-level access and host system compromise.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence