โ† Back to dashboard
clawsmith.com/claw/openclaw-security-crisis-135k-exposed-rce
โš  IssueCompetitiveFrameworkLive

OpenClaw Security Crisis: 135K Exposed Instances, RCE, AMOS Stealer

CVE-2026-25253 (CVSS 8.8) enables one-click RCE via WebSocket. CVE-2026-32913 leaks API keys over cross-origin redirects. 135K instances exposed with no auth required.

Virality Score
10,690
across 4 platforms

Score Breakdown

Reddit
4,000
HN
3,000
Issues
2,000
X
1,000

Gap Assessment

CompetitiveMarket has established players

SecureClaw, NanoClaw, Cisco DefenseClaw, Palo Alto, NVIDIA OpenShell all address this. Well-covered by established vendors.

Frequently Asked Questions