Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

31–40 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#31
post #27

Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people

Until recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523...

I have used openclaw pretty long but at no point it has proposed doing anything like that.

Re: OpenClaw privilege escalation vulnerability

#32
I don't use OpenClaw, but I still run my Claude Code and Codex as limited macOS user accounts and just have a script `become-agent [cmd ...]` that does some sudo stuff to run as the limited user so they don't have any of my environment or directory access, or really any system-level admin access at all. They can use and write to their home directories as usual, which makes things easier to configure since those CLI harnesses really like when $HOME is configured and works as expected.

It's a good compromise between running as me and full sandbox-exec. Multi-user Unix-y systems were designed for this kind of stuff since decades ago.

Re: OpenClaw privilege escalation vulnerability

#34
post #27

Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people

Until recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523...

Not true. So many people love to come out of the woodwork on these openclaw posts who have no first hand knowledge of the software. It is stunning.

Re: OpenClaw privilege escalation vulnerability

#36

Earlier quoted context omitted.

It does not need access to your full machine. It can literally run in a vps.

How do you think the vibe-coding layman audience is using OpenClaw?

Hostinger vps if youtube is any indication. Also its actually hard for a layman to run this software.

Re: OpenClaw privilege escalation vulnerability

#38
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

1/5 rounds to “probably” when discussing security.

The 135k number appears to be pulled out of thin air? No idea where the 65% comes from. The command the post gives to list paired devices isn't correct. These are red flags.

Re: OpenClaw privilege escalation vulnerability

#40
post #33
post #20

Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y

More than 25% of users seems like a pretty accurate "probably".

Today I learned nobody agrees on what the word "probably" means.
Post reply on HN