Security Advisory: CVE-2026-30741

March 10, 2026 ยท View on GitHub

Product: OpenClaw Agent Platform Affected Versions: v2026.2.6 and earlier Vulnerability Type: Remote Code Execution (RCE) via Request-Side Prompt Injection Description: A lack of integrity validation for upstream API requests allows for request-stream poisoning. This induces high-performance models to generate unauthorized terminal commands executed via MCP tools without human confirmation.

๐Ÿ“บ Proof of Concept (PoC)

Figure 1: Demonstration of RCE via Request-Side Prompt Injection

External Mirror: Bilibili (BV1LoFazeEBM)


Credit: Namedless Reference: CNVD-2026-11444