CVE 8.4 HIGH

OpenClaw Affected by Unauthenticated Local RCE via WebSocket config.apply_CVE-2026-25593

8.4 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability is fixed in 2026.1.20.

Basic Information

ID CVE-2026-25593
Source GitHub_M
Published Feb 6, 2026 at 20:56

Affected Product

Vendor openclaw
Product openclaw
Version < 2026.1.20
Affected Versions openclaw openclaw < 2026.1.20

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.