Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-30741 — Proof-of-concept demonstrating remote code execution via request-side prompt injection in OpenClaw Agent Platform, exploiting lack of integrity validation to execute unauthorized terminal commands through MCP tools. | Kitploit
Tools/GitHubGitHub/named1ess/cve-2026-30741
Vulnerability AnalysisExploitationWeb Application ExploitationAI Security
GitHubnamed1ess/cve-2026-30741

CVE-2026-30741

Proof-of-concept demonstrating remote code execution via request-side prompt injection in OpenClaw Agent Platform, exploiting lack of integrity validation to execute unauthorized terminal commands through MCP tools.

View Repository
45 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Security Advisory: CVE-2026-30741

Product: OpenClaw Agent Platform Affected Versions: v2026.2.6 and earlier Vulnerability Type: Remote Code Execution (RCE) via Request-Side Prompt Injection Description: A lack of integrity validation for upstream API requests allows for request-stream poisoning. This induces high-performance models to generate unauthorized terminal commands executed via MCP tools without human confirmation.

📺 Proof of Concept (PoC)

Your browser does not support the video tag.

Figure 1: Demonstration of RCE via Request-Side Prompt Injection

External Mirror: Bilibili (BV1LoFazeEBM)


Credit: Namedless Reference: CNVD-2026-11444

Download Tool