OpenClaw AI agent one-click RCE with 40,000+ exposed instances
A flaw in the OpenClaw personal AI agent's control UI let a single malicious link steal its auth token and run code, even on local installs. Scans found more than 40,000 exposed instances, many leaking API keys, messaging tokens and chat history.
- Disclosed
- 3 Feb 2026
- Organization
- OpenClaw users
- Vendor
- Any model
- Product
- OpenClaw (open source)
- Type of AI
- AI agent
- How it happened
- Leaky AI product: App flaw
- Harm
- Data exposed
- Data involved
- Credentials, Chat logs
- Reach
- No known access
- Severity
- Low
- Model at fault
- No
- Status
- Confirmed (research, no known victims)
- Vulnerability IDs
- CVE-2026-25253