What is CVE-2026-66421?
OpenClaw Dashboard contains a stored cross-site scripting vulnerability allowing unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser. This is achieved by injecting HTML markup into agent transcript messages processed via the sessions API. Strict input sanitization and output encoding are recommended to mitigate the risk.
Azərbaycanca: OpenClaw Dashboard məhsulunda saxlanılan XSS (Stored Cross-Site Scripting) zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış uzaqdan hücumçuya agent transkript mesajlarına HTML kodu yeritməklə administrator brauzerində ixtiyari JavaScript kodunu icra etməyə imkan verir. İstismarın qarşısını almaq üçün daxil olan məlumatların ciddi sanitizasiyası və çıxışın kodlaşdırılması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-66421 require authentication?
No, this stored XSS vulnerability can be exploited by an unauthenticated remote attacker through HTML injection into agent transcript messages.
What measures are recommended to mitigate CVE-2026-66421?
Strict input sanitization and output encoding are recommended to prevent exploitation of this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.