
Proof-of-concept demonstrating remote code execution via request-side prompt injection in OpenClaw Agent Platform, exploiting lack of integrity validation to execute unauthorized terminal commands through MCP tools.
Product: OpenClaw Agent Platform Affected Versions: v2026.2.6 and earlier Vulnerability Type: Remote Code Execution (RCE) via Request-Side Prompt Injection Description: A lack of integrity validation for upstream API requests allows for request-stream poisoning. This induces high-performance models to generate unauthorized terminal commands executed via MCP tools without human confirmation.
Figure 1: Demonstration of RCE via Request-Side Prompt Injection
External Mirror: Bilibili (BV1LoFazeEBM)
Credit: Namedless Reference: CNVD-2026-11444