Appsecure logo

CVE-2026-25593: High Vulnerability in OpenClaw

A high-severity vulnerability in OpenClaw allows unauthenticated local clients to exploit the Gateway WebSocket API for command injection. Organizations must patch immediately to protect their systems.

HIGHCVSS 8.4 · Published February 6, 2026

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2026-25593 is a high-severity vulnerability in OpenClaw, a personal AI assistant. The issue arises from an unauthenticated local client being able to exploit the Gateway WebSocket API, specifically using the config.apply function to write configuration settings. This vulnerability allows unsafe cliPath values to be set, which can later be leveraged for command discovery and command injection as the gateway user. The vulnerability is addressed in version 2026.1.20.

With a CVSS score of 8.4, this vulnerability is classified as high severity, indicating significant risk for organizations utilizing OpenClaw. The potential for command injection and unauthorized command execution poses a serious threat, especially given the local attack vector and low complexity required to exploit it.

Risk to organizations includes unauthorized access to sensitive commands and data exposure, underscoring the urgency for defenders to prioritize patching this vulnerability immediately.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.