星颖资源网

 找回密码
 立即注册
查看: 7|回复: 0

OpenClaw 被曝 1 次点击可触发 RCE,v2026.1.28 及以下受影响

[复制链接]

2万

主题

1万

回帖

11万

积分

管理员

Rank: 9Rank: 9Rank: 9

积分
110880
发表于 2026-2-2 14:55:28 | 显示全部楼层 |阅读模式


depthfirst.com (https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys)

depthfirst | 1-Click RCE To Steal Your Moltbot Data and Keys (https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys)
A technical teardown of a 1-click RCE against OpenClaw (formerly Moltbot/ClawdBot), a viral open-source AI assistant trusted by 100,000+ developers with high-privilege access. See how a settings logic flaw and a WebSocket pivot turn a single webpage...

GitHub (https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq)

1-Click RCE via Authentication Token Exfiltration From gatewayUrl (https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq)
## Summary The Control UI trusts `gatewayUrl` from the query string without validation and auto-connects on load, sending the stored gateway token in the WebSocket connect payload. Clicking a...
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

微信

社群

VIP

AI

顶部

QQ|本站内容来源网友投稿或网络转载,如果有侵权的内容,请联系我们删除。|小黑屋|人人为我,我为人人!| 星颖资源网

GMT+8, 2026-6-8 06:58 , Processed in 0.386051 second(s), 31 queries .

快速回复 返回顶部 返回列表