PT-2026-49758 · Openclaw · Openclaw
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.12
Description
Exported session HTML preserves unsafe
javascript: and data: links in generated content. This allows for the execution of browser-side scripts if a trusted operator opens the exported file and activates a malicious link. The impact depends on the operator's configuration and whether lower-trust input can reach the affected path.Recommendations
Update to version 2026.5.12.
Do not open exported session HTML from untrusted content in a privileged browser profile.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the session export feature when it is not needed.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw