highCVSS 8.8Vulnerability

GHSA-r2c6-8jc8-g32w

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-g8p2-7wf7-98mq. This link is maintained to preserve external references. ### Original Description OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Properties

ghsa_id
GHSA-r2c6-8jc8-g32w
summary
Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
severity
high
cvss_score
8.8
cve_id
GHSA-r2c6-8jc8-g32w
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-02-02T00:30:23Z
source_url
https://github.com/advisories/GHSA-r2c6-8jc8-g32w
ghsa_updated
2026-02-02T20:42:52Z

Related Entities (3)

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/clawdbot

HAS_WEAKNESS (1)

[Weakness]Incorrect Resource Transfer Between Spheres

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-r2c6-8jc8-g32w (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal