{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/web-application-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-66421"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenClaw Dashboard"],"_cs_severities":["critical"],"_cs_tags":["web-application-security","xss","cve-2026-66421"],"_cs_type":"advisory","_cs_vendors":["OpenClaw"],"content_html":"\u003cp\u003eOpenClaw Dashboard contains a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-66421, which allows unauthenticated remote attackers to execute arbitrary JavaScript within the context of an administrator's browser session. The vulnerability originates in the sessions API, where user-supplied agent transcript messages are stored without proper sanitization.\u003c/p\u003e\n\u003cp\u003eAttackers exploit this by injecting HTML markup containing event handler payloads, such as an \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e tag with an \u003ccode\u003eonerror\u003c/code\u003e attribute, into the transcript messages. These payloads are subsequently rendered by the OpenClaw Dashboard's default landing page through the use of \u003ccode\u003einnerHTML\u003c/code\u003e. The injection allows for the theft of administrative session tokens and the execution of unauthorized actions, including the modification of agent instruction files. Given the impact on administrative session integrity and authorization controls, this vulnerability poses a critical risk to organizations relying on OpenClaw Dashboard for infrastructure management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete compromise of an administrator's session. Potential consequences include the theft of sensitive session identifiers, unauthorized access to administrative dashboard functions, and the ability to modify critical agent instruction files, which could lead to further downstream system compromise or data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching OpenClaw Dashboard to the latest version provided by the vendor to remediate CVE-2026-66421.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for HTTP requests to the sessions API that contain suspicious HTML tags or event handlers, such as \u003ccode\u003eonerror\u003c/code\u003e, \u003ccode\u003eonload\u003c/code\u003e, or \u003ccode\u003escript\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRestrict access to the OpenClaw Dashboard administrative interface to trusted management networks to minimize the exposure to unauthenticated external actors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T23:32:25Z","date_published":"2026-07-30T23:32:25Z","id":"https://feed.craftedsignal.io/briefs/2026-07-openclaw-xss/","summary":"An unauthenticated stored XSS vulnerability in the OpenClaw Dashboard allows remote attackers to execute arbitrary JavaScript in administrative sessions via the sessions API.","title":"Stored XSS Vulnerability in OpenClaw Dashboard","url":"https://feed.craftedsignal.io/briefs/2026-07-openclaw-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Web-Application-Security","version":"https://jsonfeed.org/version/1.1"}