Stored Cross-Site Scripting Vulnerability in OpenClaw Dashboard by OpenClaw
CVE-2026-66421

8.8HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-66421?

The OpenClaw Dashboard is impacted by a stored cross-site scripting (XSS) vulnerability that enables unauthenticated remote attackers to execute arbitrary JavaScript within the administrator's browser session. This vulnerability arises from the improper handling of HTML markup in agent transcript messages, which are processed via the sessions API. Attackers can craft malicious messages containing payloads, such as an image tag with an onerror event, which is stored in the session transcript and unsanitized interpolated into the page’s innerHTML. This allows attackers to steal session tokens and make unauthorized requests to sensitive admin endpoints, including modifications to agent instruction files.

Affected Version(s)

openclaw-dashboard 1.1.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theodosis Paidakis
.