CVE-2026-25253: exploitation status and patch state
CVE-2026-25253 · CVSS 8.8 HIGH · EPSS 8%
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
Is CVE-2026-25253 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 8%.
Public exploit code: none found in monitored sources.