Executive brief
OpenClaw's Control UI (a gateway management interface) automatically connects to a WebSocket server address taken from a URL parameter without validating it, and sends authentication tokens to that connection. An attacker can craft a malicious link that tricks a user into connecting to an attacker-controlled server, stealing their gateway token. With the token, the attacker gains full operator-level access to the victim's gateway and can execute arbitrary commands on the underlying host.
Technical details
The vulnerability is a missing input validation flaw (CWE-669) in the Control UI's gatewayUrl parameter handling. The UI automatically initiates a WebSocket connection to the URL specified in the query string without any validation or user confirmation, and sends the stored gateway authentication token in the WebSocket handshake payload. An attacker can craft a link to a malicious gatewayUrl and send it to a user; when the victim clicks the link or visits a malicious site that redirects to it, the browser opens the Control UI and immediately connects to the attacker's server, exfiltrating the token. The attacker can then use this token to connect to the victim's gateway API as an authenticated operator and execute privileged actions, including arbitrary code execution on the gateway host. This attack succeeds even if the gateway only listens on loopback (127.0.0.1) because the victim's browser initiates the outbound connection on behalf of the attacker. The vulnerability was patched in version 2026.1.29 by requiring users to confirm the gateway URL in the UI before connecting.
Affected products
- OpenClaw clawdbot <=2026.1.28
Timeline
- 2026-01-31: disclosed: Advisory GHSA-g8p2-7wf7-98mq published
- 2026-01-31: patched: Fixed in version 2026.1.29
- 2026-02-02: other: GHSA-r2c6-8jc8-g32w marked as duplicate and withdrawn