CVE-2026-53841
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.
Scoring
- Severity
- LOW
- CVSS base score
- 6.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-83
- Published
- 2026-06-16
- Last modified
- 2026-06-20
Affected products
- OpenClaw OpenClaw
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-45118 — MyBB: Contact page reflected XSS
- CVE-2026-45733 — Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app
- CVE-2026-15920 — Potential cross-site scripting via URLField values in the admin
- CVE-2026-62324 — Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
- CVE-2026-59727 — Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- CVE-2026-49276 — Kirby: Self cross-site scripting (self-XSS) in the writer field
- CVE-2026-58263 — Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
- CVE-2026-48591 — Stored XSS via unescaped HTML attribute values in earmark