Stored Cross-Site Scripting Vulnerability in OpenClaw Dashboard by OpenClaw
CVE-2026-66418
9.3CRITICAL
What is CVE-2026-66418?
OpenClaw Dashboard version 3.0.0 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows unauthenticated remote attackers to inject arbitrary HTML and script payloads through a crafted username in a failed login POST request, which gets recorded in the audit log without escaping. When an administrator views the notification panel, the unescaped log entry is rendered via innerHTML. Due to a permissive Content-Security-Policy that permits inline event handlers, the attacker’s script can execute in the administrator's session. This could lead to unauthorized interactions with protected areas of the application, including agent instruction file modifications and configuration changes.
Affected Version(s)
openclaw-dashboard 3.0.0
