Openclaw cli: OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains (CVE-2026-32025)
Description
CVE-2026-32025 is a vulnerability in OpenClaw CLI versions before 2026.2.25 that allows a local browser-origin WebSocket authentication bypass on loopback deployments using password authentication. An attacker who convinces a user to open a malicious webpage can attempt to brute-force the gateway password without throttling, potentially gaining authenticated operator access. This issue is limited to local loopback access and requires a guessable password. The vulnerability is patched in version 2026.2.25.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw CLI versions <=2026.2.24 contain a browser-origin WebSocket authentication hardening gap on local loopback deployments using password authentication. The vulnerability arises from three combined factors: lack of origin checks for some non-Control-UI WebSocket clients, exemption of loopback authentication attempts from password-failure throttling, and a silent local pairing path available to browser-origin non-Control-UI clients. Exploitation requires the gateway to be reachable on loopback, password authentication enabled, the victim to open attacker-controlled web content, and the password to be guessable within feasible brute-force attempts. Successful exploitation allows an attacker to establish an authenticated operator WebSocket session and invoke control-plane methods. The issue is not an unauthenticated internet-exposed remote code execution but a local browser-origin authentication hardening gap with significant impact under these conditions. The vulnerability is fixed in version 2026.2.25 by enforcing browser-origin checks for all browser WebSocket clients beyond Control UI/Webchat, applying authentication failure throttling without loopback exemption, and blocking silent auto-pairing for non-Control-UI browser-origin clients.
Potential Impact
If exploited, an attacker can gain authenticated operator WebSocket access on the local loopback interface by brute-forcing the gateway password via a malicious webpage opened by the victim. This allows invocation of control-plane methods with operator privileges. The vulnerability does not allow unauthenticated remote code execution from the internet and requires local loopback access and user interaction.
Mitigation Recommendations
A patch is available in OpenClaw CLI version 2026.2.25 and later. Users should upgrade to this version to remediate the vulnerability. The fix enforces browser-origin checks, applies authentication failure throttling without loopback exemptions, and disables silent auto-pairing for non-Control-UI browser-origin clients. Until patched, ensure strong, non-guessable passwords are used to reduce brute-force risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-32025
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245bd12601ec6a3166bef
Added to database: 10/04/2026, 12:25:33 UTC
Last enriched: 10/04/2026, 13:04:39 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.