Stored Cross-Site Scripting Vulnerability in OpenClaw Dashboard by OpenClaw
CVE-2026-66421
8.8HIGH
What is CVE-2026-66421?
The OpenClaw Dashboard is impacted by a stored cross-site scripting (XSS) vulnerability that enables unauthenticated remote attackers to execute arbitrary JavaScript within the administrator's browser session. This vulnerability arises from the improper handling of HTML markup in agent transcript messages, which are processed via the sessions API. Attackers can craft malicious messages containing payloads, such as an image tag with an onerror event, which is stored in the session transcript and unsanitized interpolated into the page’s innerHTML. This allows attackers to steal session tokens and make unauthorized requests to sensitive admin endpoints, including modifications to agent instruction files.
Affected Version(s)
openclaw-dashboard 1.1.0
