OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.
History

Thu, 03 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Tugcantopaloglu openclaw Agent Dashboard
CPEs cpe:2.3:a:tugcantopaloglu:openclaw_agent_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Tugcantopaloglu openclaw Agent Dashboard

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tugcantopaloglu
Tugcantopaloglu openclaw-dashboard
Vendors & Products Tugcantopaloglu
Tugcantopaloglu openclaw-dashboard

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.
Title OpenClaw Dashboard Stored XSS via lastMessage Session Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-07-30T22:16:58.960Z

Updated: 2026-07-31T15:09:09.811Z

Reserved: 2026-07-27T05:16:45.792Z

Link: CVE-2026-66421

cve-icon Vulnrichment

Updated: 2026-07-31T15:06:24.741Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T23:16:53.687

Modified: 2026-09-03T19:56:47.147

Link: CVE-2026-66421

cve-icon Redhat

No data.