Cross-site scripting in OpenClaw - #VU132716

 

Cross-site scripting in OpenClaw - #VU132716

Published: May 29, 2026


Vulnerability identifier: #VU132716
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in exported session HTML when rendering markdown links into generated HTML. A remote attacker can supply content containing unsafe javascript: or data: links to execute arbitrary script in the victim's browser.

User interaction is required to open the exported file and activate the link, and the issue is limited to cases where the affected feature is enabled and reachable.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.5.12

External References

Related Security Bulletins