AgentsCVE-2026-27001 OpenClaw Working Directory Prompt InjectionGitHub Advisory·high signalXBlueskyLinkedInCopy linkDirectory paths with control chars break prompt structure and inject attacker instructions. Novel attack vector: filesystem paths as prompt injection vectors.SourceSource pageGitHub Advisory↳ Follow the threadPolicy dependency / Stack layerLangChain ships a first-party integration that deliberately does not wrap the vendor's SDKGitHubStack layer / Threat patternKilocode 7.7.5 adds @model, @past-chats and @worktrees mentions and fixes a session-switching memory leakGitHubStack layerClaude Code strips invisible Unicode from prompts and shows you the cleaned version before sendingGitHubPolicy dependency / Stack layerOpenAI Agents SDK 0.22.3 aligns conditional approvals with validated tool argumentsGitHub ReleasesStack layerGitHub Next ships LocalJev and documents plainly that its probabilities are self-reported, not read from logitsGitHub (githubnext/localjev)Stack layerAnthropic open-sources 36 inference optimization kits for protein and genomics models, ~4x average speedup in under four weeksAnthropicContrastCodex-X is a Rust desktop manager for the Codex CLI with provider switching and prompt injection, at 3,286 stars in ten weeksGitHub TrendingStack layer / ContrastMiniMax open-sources its terminal coding agent under MIT with bring-your-own-model supportGitHub / MiniMax-AI (via r/LocalLLaMA, 125 upvotes)