This advisory has been withdrawn because it is a duplicate of GHSA-w9hf-3pp7-pvxv. This link is maintained to preserve external references.
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.
{
"cwe_ids": [
"CWE-83"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-18T20:13:59Z",
"nvd_published_at": "2026-06-16T19:17:00Z",
"severity": "LOW"
}