PT-2026-24720 · Git+1 · Openclaw

Namedless

·

Published

2026-03-11

·

Updated

2026-03-17

·

CVE-2026-30741

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw Agent Platform version 2026.2.6
Description A remote code execution (RCE) issue exists in OpenClaw Agent Platform version 2026.2.6. This allows attackers to execute arbitrary code through a Request-Side prompt injection attack. The vulnerability poses a severe risk to AI automation pipelines and DPI. The attack vector involves manipulating requests to trigger the execution of unintended code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30741

Affected Products

Openclaw