Multiple OpenClaw AI assistant vulnerabilities disclosed, including prompt injection paths
Five CVEs were published for the OpenClaw personal AI assistant (formerly Clawdbot) covering prompt injection via untrusted Slack channel metadata and unsanitized workspace paths, a misleading macOS deep-link confirmation dialog that could lead to arbitrary command execution, local file exfiltration via the Feishu extension's sendMediaFeishu tool, and path traversal in browser download helpers. All issues were fixed in releases 2026.2.3 through 2026.2.15.
Disclosed 19 February 2026 · Record updated 13 September 2026
Impact
Attackers able to influence Slack channel metadata, workspace directory names, tool calls or deep links could inject instructions into the agent's system prompt, exfiltrate local files such as /etc/passwd, write files outside the intended downloads directory, or trick users into approving commands that differ from the visible preview, potentially leading to arbitrary command execution.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24764
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26320
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26321
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26972
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27001
