CVE Feed

    Dashboard / CVE / CVE-2026-66421

    CVE-2026-66421

    OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.

    Published:Jul 30, 2026
    Last Modified:Sep 3, 2026
    EPS:Jul 30, 2026
    EPSS Score:0.00468
    CVSS Score:9.3

    Affected Products

    Vendor
    Tugcantopaloglu
    Product
    Openclaw-dashboard
    Vendor
    Tugcantopaloglu
    Product
    Openclaw Agent Dashboard

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High