QSearchQSearch

CVE-2026-53841

6.1 MEDIUM

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and da...

Published: 2026-06-16 · Last updated: 2026-06-16

Severity and scoring

CVSS
6.1 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE
CWE-83

Description

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-53722 Nuxt is an open-source web development framework for Vue.js (5.4 MEDIUM)
  • CVE-2026-45669 Nuxt is an open-source web development framework for Vue.js (5.4 MEDIUM)
  • CVE-2026-8245 Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection (5.4 MEDIUM)