CVE-2026-25253 | OpenClaw/Clawdbot/Moltbot up to 2026.1.28 Websocket Connection gatewayUrl resource transfer (GHSA-g8p2-7wf7-98mq)
A vulnerability labeled as very critical has been found in OpenClaw, Clawdbot and Moltbot up to 2026.1.28. This impacts an unknown function of the component Websocket Connection Handler. Such manipulation of the argument gatewayUrl leads to incorrect resource transfer.
This vulnerability is uniquely identified as CVE-2026-25253. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.