Skip to main content
EPSS 0.5%top 58%

Openclaw cli: OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains (CVE-2026-32025)

0
High
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

CVE-2026-32025 is a vulnerability in OpenClaw CLI versions before 2026.2.25 that allows a local browser-origin WebSocket authentication bypass on loopback deployments using password authentication. An attacker who convinces a user to open a malicious webpage can attempt to brute-force the gateway password without throttling, potentially gaining authenticated operator access. This issue is limited to local loopback access and requires a guessable password. The vulnerability is patched in version 2026.2.25.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
>=2026.1.29 <2026.2.25

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 13:04:39 UTC

Technical Analysis

OpenClaw CLI versions <=2026.2.24 contain a browser-origin WebSocket authentication hardening gap on local loopback deployments using password authentication. The vulnerability arises from three combined factors: lack of origin checks for some non-Control-UI WebSocket clients, exemption of loopback authentication attempts from password-failure throttling, and a silent local pairing path available to browser-origin non-Control-UI clients. Exploitation requires the gateway to be reachable on loopback, password authentication enabled, the victim to open attacker-controlled web content, and the password to be guessable within feasible brute-force attempts. Successful exploitation allows an attacker to establish an authenticated operator WebSocket session and invoke control-plane methods. The issue is not an unauthenticated internet-exposed remote code execution but a local browser-origin authentication hardening gap with significant impact under these conditions. The vulnerability is fixed in version 2026.2.25 by enforcing browser-origin checks for all browser WebSocket clients beyond Control UI/Webchat, applying authentication failure throttling without loopback exemption, and blocking silent auto-pairing for non-Control-UI browser-origin clients.

Potential Impact

If exploited, an attacker can gain authenticated operator WebSocket access on the local loopback interface by brute-forcing the gateway password via a malicious webpage opened by the victim. This allows invocation of control-plane methods with operator privileges. The vulnerability does not allow unauthenticated remote code execution from the internet and requires local loopback access and user interaction.

Mitigation Recommendations

A patch is available in OpenClaw CLI version 2026.2.25 and later. Users should upgrade to this version to remediate the vulnerability. The fix enforces browser-origin checks, applies authentication failure throttling without loopback exemptions, and disables silent auto-pairing for non-Control-UI browser-origin clients. Until patched, ensure strong, non-guessable passwords are used to reduce brute-force risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-32025
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6ac245bd12601ec6a3166bef

Added to database: 10/04/2026, 12:25:33 UTC

Last enriched: 10/04/2026, 13:04:39 UTC

Last updated: 10/04/2026, 16:08:37 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses