CVE-2026-30741: Code Injection
Published Mar 11, 2026
·Updated
A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.
Affected Software
2 affected components
OpenClaw Agent Platform
OpenClaw Openclaw Node.js<=2026.2.6
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30741?
CVE-2026-30741 is rated as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-30741?
To fix CVE-2026-30741, update the OpenClaw Agent Platform to the latest version that includes security patches.
3
What type of attack is associated with CVE-2026-30741?
CVE-2026-30741 is associated with a Request-Side prompt injection attack allowing arbitrary code execution.
4
Which software is affected by CVE-2026-30741?
CVE-2026-30741 affects the OpenClaw Agent Platform version 2026.2.6.
5
What are the consequences of CVE-2026-30741 if exploited?
Exploitation of CVE-2026-30741 can lead to unauthorized access and execution of arbitrary code on affected systems.