
CVE-2026-28464: researchers found that OpenClaw's agent fails to validate user intent before executing high-risk shell ops. Arbitrary code execution via prompt injection. AI agents running with root-level trust is a design choice. A bad one.
Post summary
Researchers have identified CVE-2026-28464, where OpenClaw’s agent allows arbitrary code execution through prompt injection due to missing intent validation for high‑risk shell operations.



