top of page
perceptive_background_267k.jpg

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script …

Published:

30 juli 2026 om 00:00:00

Alert date:

31 juli 2026 om 00:03:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities, Identity & Access

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting (XSS) vulnerability tracked as CVE-2026-66418. Unauthenticated remote attackers can inject arbitrary HTML and JavaScript by submitting a crafted username in a failed login POST request. The malicious input is recorded verbatim in the audit log without sanitization. When an administrator views the notification panel, the unescaped log entry is rendered via innerHTML. A permissive Content-Security-Policy allows inline event handlers, enabling the payload to execute in the administrator's browser session. This can allow attackers to interact with authenticated endpoints, edit agent instruction files, and make configuration changes, effectively leading to administrator account takeover.

Technical details

Mitigation steps:

Affected products:

OpenClaw Dashboard v3.0.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page