Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key โ†’
โ† Back to dashboard
clawsmith.com/signal/cve-2026-30741-rce-prompt-injection-openclaw
โš  IssueWide OpenLive

CVE-2026-30741: OpenClaw RCE via Request-Side Prompt Injection in v2026.2.6

Critical remote code execution vulnerability in OpenClaw Agent Platform v2026.2.6. Attackers execute arbitrary code via request-side prompt injection that bypasses integrity validation, inducing models to generate unauthorized terminal commands executed via MCP tools without human confirmation. CWE-94. Disclosed March 11, 2026. Affects all OpenClaw instances running v2026.2.6 or earlier.

Score Breakdown

GitHub
4

Gap Assessment

Wide OpenNo dedicated solution exists

No automated detection or runtime mitigation for request-side prompt injection in agent platforms

Frequently Asked Questions