OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://hackread.com/openclaw-vulnerability-openclaw-hijack-ai-agents/
https://www.securityweek.com/vulnerability-allows-hackers-to-hijack-openclaw-ai-assistant/
https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html
https://github.com/cain66666/openclaw-hardening-check
https://github.com/Delta117-117/openclaw-hardening
https://github.com/kobayashi-shuto-0105/claude-code-cve-genie
https://github.com/1392081456/sigma-detection-rules
https://github.com/siyad01/agentbox
https://github.com/anthhub/awesome-claw-opus
https://github.com/ZhaoymOvO/openclaw-1click-rce-env
https://github.com/xhls008/ClawArmor
https://github.com/veryboylb/openclaw-security-hardening
https://github.com/getmilodev/milo-shield
https://github.com/FrigateCaptain/openclaw_vulnerabilities_and_solutions
https://github.com/Ckokoski/moatbot-security
https://github.com/Clawman-007/openclaw-security-vaccine
https://github.com/Joseph19820124/openclaw-vuln-report
https://github.com/adibirzu/openclaw-security-monitor
https://github.com/root-Brainoverflow/cve-crawler
https://x.com/0xacb/status/2016913750557651228
https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq
https://ethiack.com/news/blog/one-click-rce-moltbot
https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys