OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741)
Two vulnerabilities were disclosed in the OpenClaw agent platform: an SSRF issue in the Feishu extension (CVE-2026-28451) that lets attackers trigger fetches of attacker-controlled or internal URLs via tool calls influenced by prompt injection, and a remote code execution flaw (CVE-2026-30741) in v2026.2.6 exploitable through request-side prompt injection.
Disclosed 5 March 2026 · Record updated 13 September 2026
Impact
Attackers can trigger requests to internal services and re-upload responses as Feishu media, and can execute arbitrary code on affected OpenClaw installations.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-28451
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30741
