The 11-Point OpenClaw
Hardening Checklist
Updated for ClawJacked (CVE-2026-25253) — the WebSocket brute-force vulnerability affecting all versions before 2026.2.25. Secure your deployment in under 2 hours. Free PDF.
CVE-2026-25253 (ClawJacked) lets attackers brute-force WebSocket auth and hijack sessions. 1,184+ malicious skills on ClawHub. 135,000+ internet-exposed instances. Most deployments are running default configs. This checklist fixes the 11 things that matter most.
What's inside
- ClawJacked (CVE-2026-25253) remediation — version check + WebSocket hardening
- Device audit — detect unauthorized registrations from brute-force attacks
- Critical CVE patches beyond ClawJacked
- Gateway authentication configuration
- File system and network lockdown
- Skill auditing process
- API cost guardrails
- Monitoring setup
Written by Peter K. — Security Architect with 20+ years in the tech industry.