Sev0

AI security incidents, tracked

All incidents / Leaky AI product

OpenClaw AI agent one-click RCE with 40,000+ exposed instances

OpenClaw users, disclosed 2 Feb 2026 Leaky AI product Data exposed Low

What happened

A flaw in the OpenClaw personal AI agent's control UI let a single malicious link steal its auth token and run code, even on local installs. Scans found more than 40,000 exposed instances, many leaking API keys, messaging tokens and chat history.

OpenClaw is a popular open-source personal AI agent that runs on a user's own computer, connects to email and messaging apps and can run system commands, so it often holds very broad permissions. Its browser-based Control UI accepted a gateway address from the page's web address without checking it and connected to it automatically, sending the user's stored access token along. A crafted link or malicious web page could therefore hand the token to an attacker, who could then use the victim's own browser to connect to their local OpenClaw instance, loosen its sandbox and tool settings and run commands. Because the victim's browser made the connection, it worked even on installations only listening on the local machine. By the time it was disclosed, scans had found more than 40,000 OpenClaw instances exposed on the internet, many leaking API keys, messaging tokens and chat history.

How it happened

Leaky AI product: App flaw. A security flaw in an AI application, such as broken login or access checks, let someone reach data they should not have seen.

The software involved works with many AI models, so no single model maker was involved. The product was OpenClaw, which is open source, a type of AI agent. Vulnerability IDs: CVE-2026-25253, GHSA-g8p2-7wf7-98mq.

Impact

Data was exposed. Data involved: credentials and chat logs. There is no evidence that anyone actually accessed the data.

Severity is rated Low, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm. This was a research finding: no real victims are known.

It became public on 2 Feb 2026.

The maintainer fixed the flaw in version 2026.1.29, released on 30 January 2026, and published an advisory on 2 February urging users to upgrade.

Sources

  1. https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq
  2. https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html

Related incidents

Cite as: Sev0, "OpenClaw AI agent one-click RCE with 40,000+ exposed instances", https://sev0.fyi/incidents/2026-02-02-openclaw-one-click-rce/. Data for this record: incidents.json.