Security Advisory: CVE-2026-30741
March 10, 2026 ยท View on GitHub
Product: OpenClaw Agent Platform Affected Versions: v2026.2.6 and earlier Vulnerability Type: Remote Code Execution (RCE) via Request-Side Prompt Injection Description: A lack of integrity validation for upstream API requests allows for request-stream poisoning. This induces high-performance models to generate unauthorized terminal commands executed via MCP tools without human confirmation.
๐บ Proof of Concept (PoC)
Figure 1: Demonstration of RCE via Request-Side Prompt Injection
External Mirror: Bilibili (BV1LoFazeEBM)
Credit: Namedless Reference: CNVD-2026-11444