Ming Blog

Not everything that counts can be counted, and not everything that's counted truly counts

OpenClaw安全实战系列(三):利用网关劫持实现 OpenClaw 控制端 1-Click RCE (CVE-2026-25253)

深入解析 OpenClaw 控制端 UI 关键逻辑漏洞 CVE-2026-25253,CVSS 8.8,攻击者可通过 1-Click 操作劫持网关地址、窃取身份令牌并实现远程代码执行。