CVE-2026-27009

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without script-context-safe escaping. A crafted value containing `</script>` could break out of the script tag and execute attacker-controlled JavaScript in the Control UI origin. Version 2026.2.15 removed inline script injection and serve bootstrap config from a JSON endpoint and added a restrictive Content Security Policy for the Control UI (`script-src 'self'`, no inline scripts).
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-37gc-85xm-2ww6 - Exploit, Vendor Advisory, Patch () https://github.com/openclaw/openclaw/security/advisories/GHSA-37gc-85xm-2ww6 - Exploit, Patch, Vendor Advisory
Summary
  • (es) OpenClaw es un asistente personal de IA. Antes de la versión 2026.2.15, existía un problema de XSS almacenado en la interfaz de usuario de control de OpenClaw al renderizar la identidad del asistente (nombre/avatar) en una etiqueta `` podría escapar de la etiqueta de script y ejecutar JavaScript controlado por el atacante en el origen de la interfaz de usuario de control. La versión 2026.2.15 eliminó la inyección de scripts en línea y sirve la configuración de arranque desde un endpoint JSON, y añadió una Política de Seguridad de Contenido restrictiva para la interfaz de usuario de control (`script-src 'self'`, sin scripts en línea).

20 Feb 2026, 17:41

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/3b4096e02e7e335f99f5986ec1bd566e90b14a7e - () https://github.com/openclaw/openclaw/commit/3b4096e02e7e335f99f5986ec1bd566e90b14a7e - Patch
References () https://github.com/openclaw/openclaw/commit/adc818db4a4b3b8d663e7674ef20436947514e1b - () https://github.com/openclaw/openclaw/commit/adc818db4a4b3b8d663e7674ef20436947514e1b - Patch
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.15 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.15 - Product, Release Notes
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-37gc-85xm-2ww6 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-37gc-85xm-2ww6 - Exploit, Vendor Advisory, Patch

20 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 00:16

Updated : 2026-06-17 10:26


NVD link : CVE-2026-27009

Mitre link : CVE-2026-27009

CVE.ORG link : CVE-2026-27009


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')