Описание
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary javascript by injecting malicious mimeType values in image content blocks. Attackers can craft session entries with specially crafted mimeType attributes that break out of the img src data-URL context to achieve cross-site scripting when exported HTML is opened.
Ссылки
- Issue Tracking
- ExploitVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.2.23 (исключая)
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 5%
0.00148
Низкий
4.6 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.6
github
5 месяцев назад
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation
EPSS
Процентиль: 5%
0.00148
Низкий
4.6 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79