CVE-2026-53841
6.1 MEDIUMOpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and da...
Published: 2026-06-16 · Last updated: 2026-06-16
Severity and scoring
- CVSS
- 6.1 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- CWE
- CWE-83
Description
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-53722 — Nuxt is an open-source web development framework for Vue.js (5.4 MEDIUM)
- CVE-2026-45669 — Nuxt is an open-source web development framework for Vue.js (5.4 MEDIUM)
- CVE-2026-8245 — Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection (5.4 MEDIUM)