CVE-2026-25157 | OpenClaw/Clawdbot/Moltbot up to 2026.1.28 sshNodeCommand os command injection (GHSA-q284-4pvr-m585)
A vulnerability categorized as critical has been discovered in OpenClaw, Clawdbot and Moltbot up to 2026.1.28. The impacted element is the function sshNodeCommand. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-25157. The attack can only be performed from a local environment. No exploit is available.
It is advisable to upgrade the affected component.