Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

61–70 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#61
post #47
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

[deleted]

Re: OpenClaw privilege escalation vulnerability

#62
post #43

Well, such things were to be expected. It's easy to bash on all the people who haven't gotten the necessary IT understanding of securing such things. Of course, it's uber-dumb to run an unprotected instance. But at the same time, it's also quite cool that so many people can do interesting IT stuff now. I'm thinking basically it's a trade-off. Be able to do great stuff, live with the consequences of doing that without…

Gonna be honest. I'd rather fight climate change than have people run LLMs unsecured

Yeah... The bill is already being paid. I wonder how the life quality of my nephew (and other children) of 5 years old today will be in the near future..

Re: OpenClaw privilege escalation vulnerability

#63

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

[flagged]

Obviously I already searched the web (not specifically HN I must admit) and there were always incredibly generic non-answers that ultimately say nothing (and they assume you have 3000$ per month or 2000 Mac Minis on your desk (hyperbole)).

Re: OpenClaw privilege escalation vulnerability

#64

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc (https://github.com/sgillen/sf-civic-digest).

It also have mine automatically grabs a spot at my gym when spots are released because I always forget.

I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any time but the blast radius would be small.

Re: OpenClaw privilege escalation vulnerability

#66
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#67
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#68

Earlier quoted context omitted.

[flagged]

Obviously I already searched the web (not specifically HN I must admit) and there were always incredibly generic non-answers that ultimately say nothing (and they assume you have 3000$ per month or 2000 Mac Minis on your desk (hyperbole)).

Incredibly, one of the responses you got already is exactly one of those replies that says nothing. There's a whole bunch of words that don't actually answer the question.

Re: OpenClaw privilege escalation vulnerability

#69
post #66
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Have you met these AI companies yet?

Re: OpenClaw privilege escalation vulnerability

#70

OpenClaw creator here. This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance." The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerS…

Can you speak a little bit more to the stats in the OP?

* 135k+ OpenClaw instances are publicly exposed

* 63% of those run zero authentication. Meaning the "low privilege required" in the CVE = literally anyone on the internet can request pairing access and start the exploit chain

Is this accurate? This is definitely a very different picture then the one you paint

Post reply on HN