Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

21–30 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#21
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

But this is nothing to do with the agent being tricked. This is ordinary old-fashioned code being tricked!

Re: OpenClaw privilege escalation vulnerability

#22
post #12

OpenClaw has over 400+ security issues and vulnerabilities. [0] Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks? Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone. [0] https://github.com/opencl…

It does not need access to your full machine. It can literally run in a vps.

Re: OpenClaw privilege escalation vulnerability

#24
post #2

Earlier quoted context omitted.

[flagged]

What reason would Steinberger have for doing that? It was his hobby project.

You can’t think of a single reason?

Intelligence asset.

Useful idiot.

Plenty of reasons.

Re: OpenClaw privilege escalation vulnerability

#25
post #4
post #2

Earlier quoted context omitted.

[flagged]

In this case I'd say that it was made not to enable that, but in total disregard of its realistic uses and risks. In a sense this is less... deliberate poisoning, and more doing a bad job cutting heroin with fentanyl for distribution. Yeah the result is the same, but the cause is negligence to the point of parody rather than outright malice.

Some people are so stupid it is indistinguishable from evil.

Re: OpenClaw privilege escalation vulnerability

#27

Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people

Until recently, this was default configuration

Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263

https://github.com/openclaw/openclaw/commit/5643a934799dc523...

Re: OpenClaw privilege escalation vulnerability

#29
post #12

OpenClaw has over 400+ security issues and vulnerabilities. [0] Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks? Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone. [0] https://github.com/opencl…

It does not need access to your full machine. It can literally run in a vps.

How do you think the vibe-coding layman audience is using OpenClaw?

Re: OpenClaw privilege escalation vulnerability

#30
post #27

Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people

Until recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523...

Since pretty much the beginning it wasn't and the documentation explicitly warned not to make it public, exposing it to the internet. It included information on how you can properly forward the gateway port to your machine without opening it up to the internet.
Post reply on HN