Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people
Until recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523...
OpenClaw privilege escalation vulnerability
31–40 of 306 posts
Re: OpenClaw privilege escalation vulnerability
#32It's a good compromise between running as me and full sandbox-exec. Multi-user Unix-y systems were designed for this kind of stuff since decades ago.
Re: OpenClaw privilege escalation vulnerability
#33Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
Re: OpenClaw privilege escalation vulnerability
#34Only if your openclaw instance is publicly exposed on the internet... which is not the case for most people
Until recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523...
Re: OpenClaw privilege escalation vulnerability
#35Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
Re: OpenClaw privilege escalation vulnerability
#36Re: OpenClaw privilege escalation vulnerability
#37Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
Re: OpenClaw privilege escalation vulnerability
#38Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
1/5 rounds to “probably” when discussing security.
Re: OpenClaw privilege escalation vulnerability
#39[flagged]
Re: OpenClaw privilege escalation vulnerability
#40Title is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
More than 25% of users seems like a pretty accurate "probably".