Cross-site scripting in OpenClaw - CVE-2026-27009
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary JavaScript in the Control UI origin.
The vulnerability exists due to cross-site scripting in the Control UI inline script rendering of assistant identity values when rendering assistant name or avatar values into an inline script block without script-context-safe escaping. A local user can set a crafted assistant identity value to execute arbitrary JavaScript in the Control UI origin.
User interaction is required for a Control UI visitor to load the affected interface.