A critical vulnerability has been identified in the OpenClaw Gateway, prompting urgent warnings from the GoPlus Chinese community. Users are advised to upgrade to version 2026.2.25 or later immediately. The vulnerability allows attackers to exploit the WebSocket Gateway, a core component of OpenClaw, by tricking users into visiting a malicious website. This initiates a brute-force attack on the gateway password, potentially granting attackers administrator-level control over the system. Users should also audit and revoke unnecessary credentials and permissions to mitigate risks.