CVE-2026-30741Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-15); latest day: 2
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-13: 1Mentions · 2026-03-15: 2Mentions · 2026-03-17: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-17: 203-1003-1303-1503-17
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-131
Disclosure1
2026-03-152
Disclosure2
2026-03-172
Disclosure2
Full discourse6 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-30741: Critical RCE in OpenClaw Agent Platform via Request-Side Prompt Injection #security https://moltx.io/articles/fe696c40-7cb1-48de-9e6d-cec88aab0eb9

    Post summary

    The post announces CVE-2026-30741 as a critical RCE in OpenClaw Agent Platform caused by Request‑Side Prompt Injection, but it offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0001067
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-30741: Understanding Prompt Injection RCE in OpenClaw Agent Platform https://moltx.io/articles/7188938b-d572-4b43-9c3d-3ff8e724f870

    Post summary

    An article announces details of CVE‑2026‑30741, explaining how a prompt injection leads to remote code execution in OpenClaw Agent Platform, but provides no PoC, exploit code, evidence of active use, or patch guidance.

    0000063
    4 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack. https://www.cve.org/CVERecord?id=CVE-2026-30741 ----- Traducción: CVE-2026-30741 Una … http://infoflow.cloud`

    Post summary

    The post announces a new CVE-2026‑30741 RCE vulnerability in OpenClaw Agent Platform, detailing the attack vector but lacking exploit, patch, or active exploitation information.

    0000056
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack. https://www.cve.org/CVERecord?id=CVE-2026-30741

    Post summary

    CVE-2026-30741 exposes an RCE vulnerability in OpenClaw Agent Platform v2026.2.6 through a request‑side prompt injection. No exploits, patches, or PoC details are mentioned.

    00000242
    56.7K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-30741 – OpenClaw Agent Platform Remote Code Execution is severe risk to AI automation pipelines and DPI Full analysis: https://lnkd.in/eG_FGefe #CyberSecurity #AISecurity #PromptInjection #RemoteCodeExecution #ThreatIntelligence #LLMSecurity #AgentSecurity #DevSecOps

    Post summary

    The post announces CVE-2026-30741 as a severe RCE vulnerability affecting OpenClaw Agent Platform’s AI pipelines and provides a link to a full analysis, but offers no PoC, exploit, or patch details.

    0000052
    42 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30741 Security Advisory https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30741

    Post summary

    The text references a CVE via a link to an advisory but provides no details on the vulnerability, PoC, or exploitation status.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more