mediumVulnerability

GHSA-r294-2894-92j3

## Summary The exported session HTML viewer allowed stored XSS when untrusted session content included raw HTML markdown tokens or unescaped metadata fields. ## Impact Opening a crafted exported HTML session could execute attacker-controlled JavaScript in the viewer context. This can expose session content in the page and enable phishing or UI spoofing in the trusted export view. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.2.22-2` - Patched version (released): `>= 2026.2.23` ## Technical Details The exporter rendered markdown with `marked.parse(...)` and inserted HTML via `innerHTML`, but did not override the `html` renderer token path. Raw HTML (for example `<img ... onerror=...>`) was passed through. Additional tree/header metadata fields were interpolated without escaping in the export template. ## Reproduction 1. Create a session containing content like `<img src=x onerror=alert(1)>`. 2. Export the session to HTML. 3. Open the exported file. 4. Observe script execution from injected content. ## Remediation - Added a `marked` `html(token)` renderer override that escapes raw HTML tokens. - Escaped previously unescaped tree/header metadata fields in the export template. - Added image MIME sanitization for exported data-URL image rendering. - Added regression tests for markdown/token and metadata escaping paths. ## Fix Commit(s) - `f8524ec77a3999d573e6c6b8a5055bf35c49a2e6` ## Release Process Note `patched_versions` is pre-set to the released version (`>= 2026.2.23`). This advisory now reflects released fix version `2026.2.23`. OpenClaw thanks @allsmog for reporting.

Properties

ghsa_id
GHSA-r294-2894-92j3
severity
medium
summary
OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering
cve_id
GHSA-r294-2894-92j3
is_ghsa_only
true
ghsa_published
2026-03-03T22:09:26Z
source_url
https://github.com/advisories/GHSA-r294-2894-92j3
ghsa_updated
2026-03-03T22:09:28Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-r294-2894-92j3 — Ninja Signal Threat Intelligence | Ninja Signal