Cross-site scripting in OpenClaw - #VU128799
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the exported HTML viewer context.
The vulnerability exists due to cross-site scripting in the exported session HTML viewer when rendering untrusted session content containing raw HTML markdown tokens or unescaped metadata fields. A remote attacker can create a crafted session and trick the victim into opening the exported HTML file to execute arbitrary JavaScript in the exported HTML viewer context.
User interaction is required to open a crafted exported HTML session file.