Executive brief
Clawdbot is a Node.js application that provides a control interface for gateway instances. An attacker can craft a malicious link that tricks an authenticated user into revealing their authentication token, allowing the attacker to gain full operator access to the victim's gateway and execute arbitrary code on it. The attack works even when the gateway is configured to accept connections only from the local machine.
Technical details
The vulnerability stems from a lack of input validation on the gatewayUrl parameter in the query string combined with auto-connect behavior on page load. The Control UI accepts a gatewayUrl parameter without validation and automatically connects to it, transmitting the stored gateway authentication token in the WebSocket connect payload. An attacker can craft a malicious URL or trick a user into visiting an attacker-controlled website, causing the victim's browser to exfiltrate the token to an attacker-controlled server. Once obtained, the attacker can connect to the victim's gateway API with operator-level privileges, modify configurations (including sandbox and tool policies), and invoke privileged actions leading to remote code execution on the gateway host. This attack bypasses network isolation because the victim's browser initiates the outbound connection. The fix requires users to manually confirm new gateway URLs in the UI before connecting.
Affected products
- OpenClaw Clawdbot <= 2026.1.28
Timeline
- 2026-02-02: disclosed: Published on GitHub
- 2026-02-02: patched: Fixed in version 2026.1.29