tpaidakis▌
Writeups About

Innerhtml

2026-08-03 7 min read CVE-2026-66418CVE-2026-66421 javascriptxssdashboardinnerhtmlopenclaw-dashboard

Your login failed. The attack didn't. Stored XSS in OpenClaw Dashboard

Two stored XSS bugs in OpenClaw Dashboard, both the same missing encode on the way to innerHTML. One is reachable by an unauthenticated visitor through the login form, the other fires on a background timer with no admin click at all.

Theodosis Paidakis · Offensive Security
RSS