Executive brief
OpenClaw, a tool used for managing and exporting session data, contains a security flaw in its HTML export feature. If an attacker provides malicious content that is later exported to an HTML file, they can execute unauthorized scripts in the browser of any administrator or operator who opens that file and clicks a link. This could lead to unauthorized actions being performed in the context of the operator's session.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in OpenClaw versions prior to 2026.5.12. The root cause is the improper neutralization of 'javascript:' and 'data:' URIs within markdown links when rendering exported session HTML (CWE-83/CWE-79). An attacker can inject malicious links into a session; if a trusted operator subsequently exports that session and interacts with the malicious link in a browser, the attacker's script will execute. This is a client-side attack requiring user interaction. The vulnerability is addressed in version 2026.5.12.
Affected products
- OpenClaw openclaw < 2026.5.12
Timeline
- 2026-05-28: advisory: Original advisory GHSA-w9hf-3pp7-pvxv published
- 2026-06-16: disclosed: NVD publication of CVE-2026-53841
- 2026-06-18: patched: Duplicate advisory withdrawn and fix confirmed in 2026.5.12