CVE-2026-27009 | OpenClaw/Clawdbot/Moltbot up to 2026.2.14 JSON Endpoint cross site scripting (GHSA-37gc-85xm-2ww6 / WID-SEC-2026-0459)
A vulnerability described as problematic has been identified in OpenClaw, Clawdbot and Moltbot up to 2026.2.14. This affects an unknown part of the component JSON Endpoint. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-27009. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.