Executive brief
OpenClaw is an AI automation tool that exports session records to HTML format. A vulnerability in the HTML exporter fails to validate image MIME type metadata before inserting it into HTML attributes, allowing attackers to inject malicious JavaScript code. When a user opens an exported session containing a crafted image entry, the injected code executes in their browser, potentially enabling account takeover or data theft.
Technical details
The vulnerability exists in src/auto-reply/reply/export-html/template.js where img.mimeType values are interpolated directly into HTML data-URL attributes (lines 1032 and 1306) without validation or escaping. By crafting a session entry with a malicious mimeType value (e.g., image/png" onerror="alert(1) ), an attacker can break out of the attribute context and inject arbitrary event handlers. The attack requires the ability to control image content blocks in session data, either through crafted tool results or session manipulation. Exploitation is straightforward: export the malicious session to HTML, then open the file to trigger the injected JavaScript. The fix implements a sanitizeImageMimeType() helper function that validates MIME types against a whitelist of known image formats and falls back to application/octet-stream for unrecognized values.
Affected products
- OpenClaw OpenClaw <= 2026.2.22
Timeline
- 2026-02-24: disclosed
- 2026-02-23: patched: Fix merged in PR #24140; patched version 2026.2.23 released
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2ww6-868g-2c56
- https://github.com/openclaw/openclaw/pull/24140
- https://github.com/openclaw/openclaw/commit/f3adf142c195000cbde31200626a1d8c8b716df9
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-html-injection-via-unvalidated-image-mime-type-in-data-url-interpolation