clawsmith.com/signal/cve-2026-35650-prompt-injection-sandbox-policy-bypass
⚠ IssueUnknownVulnerabilityLive
CVE-2026-35650: Prompt Injection Rewrites OpenClaw Sandbox Policies, Plugin Permissions, and Routing Hooks
Model outputs with crafted prompt-injection payloads can override operator safeguards by writing to trusted configuration paths. Sandbox policies, plugin permissions, routing hooks, MCP server settings, and filesystem protections are all reachable through the bug. Configuration patching did not adequately cover several sensitive operator-trusted settings. Fixed in v2026.4.20.
Product Idea from this Signal
A policy enforcement daemon that blocks prompt-injection config rewrites on self-hosted OpenClaw agents running on NVIDIA RTX hardware
435 ▲SECURITYLOCAL-AINVIDIAOPEN-SOURCEDEVTOOLSIDECAR
CompetitiveView Opportunity →
Score Breakdown
Issues
22
HN
8
Social Proof 3 sources
Frequently Asked Questions
Virality Score
30
across 0 platforms
Details
Signalissue
EcosystemVulnerability
Sources3
Platforms0
Updated4d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →