PT-2026-49758 · Openclaw · Openclaw

·

CVE-2026-53841

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.12
Description Exported session HTML preserves unsafe javascript: and data: links in generated content. This allows for the execution of browser-side scripts if a trusted operator opens the exported file and activates a malicious link. The impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Recommendations Update to version 2026.5.12. Do not open exported session HTML from untrusted content in a privileged browser profile. Keep channel and tool allowlists narrow. Avoid sharing one Gateway between mutually untrusted users. Disable the session export feature when it is not needed.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53841
GHSA-6XCG-6Q43-RJ2V
GHSA-W9HF-3PP7-PVXV

Affected Products

Openclaw