Code Injection in OpenClaw - CVE-2026-27165
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to inject attacker-controlled prompt text into the LLM context.
The vulnerability exists due to improper input validation in src/acp/event-mapper.ts when interpolating ACP resource_link metadata into prompt text. A remote attacker can supply crafted title or uri fields to inject attacker-controlled prompt text into the LLM context.