Prompt Injection via vCards and Email Enables RCE and Data Exfiltration in OpenClaw Agent
Two independent research teams demonstrated that OpenClaw, a self-hosted AI agent, is vulnerable to prompt injection attacks delivered through shared contacts, vCards, location pins, and plain emails …