Sev0AI security incidents, tracked

All incidents / Leaky AI product

OpenClaw AI agent one-click RCE with 40,000+ exposed instances

OpenClaw users, disclosed 3 Feb 2026. Leaky AI product Data exposed Low

A flaw in the OpenClaw personal AI agent's control UI let a single malicious link steal its auth token and run code, even on local installs. Scans found more than 40,000 exposed instances, many leaking API keys, messaging tokens and chat history.

Disclosed
3 Feb 2026
Organization
OpenClaw users
Vendor
Any model
Product
OpenClaw (open source)
Type of AI
AI agent
How it happened
Leaky AI product: App flaw
Harm
Data exposed
Data involved
Credentials, Chat logs
Reach
No known access
Severity
Low
Model at fault
No
Status
Confirmed (research, no known victims)
Vulnerability IDs
CVE-2026-25253

Sources

  1. https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "OpenClaw AI agent one-click RCE with 40,000+ exposed instances", https://sev0.fyi/incidents/2026-02-03-openclaw-one-click-rce/