Cross-site scripting in OpenClaw - #VU128799
Published: May 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the exported HTML viewer context.
The vulnerability exists due to cross-site scripting in the exported session HTML viewer when rendering untrusted session content containing raw HTML markdown tokens or unescaped metadata fields. A remote attacker can create a crafted session and trick the victim into opening the exported HTML file to execute arbitrary JavaScript in the exported HTML viewer context.
User interaction is required to open a crafted exported HTML session file.