Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

OpenClaw agent platform: SSRF and RCE via prompt injection (CVE-2026-28451, CVE-2026-30741)

Two vulnerabilities were disclosed in the OpenClaw agent platform: an SSRF issue in the Feishu extension (CVE-2026-28451) that lets attackers trigger fetches of attacker-controlled or internal URLs via tool calls influenced by prompt injection, and a remote code execution flaw (CVE-2026-30741) in v2026.2.6 exploitable through request-side prompt injection.

Disclosed 5 March 2026 · Record updated 13 September 2026

Impact

Attackers can trigger requests to internal services and re-upload responses as Feishu media, and can execute arbitrary code on affected OpenClaw installations.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-28451
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30741