PT-2026-49758 · Openclaw · Openclaw

Edward-X

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53841

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-53841

Affected Products

Openclaw