Stored Cross-Site Scripting Vulnerability in OpenClaw Dashboard by OpenClaw
CVE-2026-66418

9.3CRITICAL

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-66418?

OpenClaw Dashboard version 3.0.0 is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows unauthenticated remote attackers to inject arbitrary HTML and script payloads through a crafted username in a failed login POST request, which gets recorded in the audit log without escaping. When an administrator views the notification panel, the unescaped log entry is rendered via innerHTML. Due to a permissive Content-Security-Policy that permits inline event handlers, the attacker’s script can execute in the administrator's session. This could lead to unauthorized interactions with protected areas of the application, including agent instruction file modifications and configuration changes.

Affected Version(s)

openclaw-dashboard 3.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theodosis Paidakis
.