Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

141–150 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#141

Earlier quoted context omitted.

so far, I've used it to kill a bunch of time trying to get it to respond to "Hi @Kirk" in a private Slack channel. ...and to laugh a little every time it calls me "commander" or asks "What's the next mission?" or (and this is the best one) it uses the catchphrase I gave it which is "it's probably fine" (and it uses it entirely appropriately...I think there must have been a lot of sarcasm in qwen 3.5's training data)…

So basically an eggdrop like we had in the 90s except, by the sounds of it, less useful and considerably less fun.

Having this in a discord is actually like having an eggdrop on steroids. I would of lost my mind having this on efnet in the late 90s.

Re: OpenClaw privilege escalation vulnerability

#143

The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.

There are like 10 openclaw clones out there. If you prefer security over features, just pick up another one.

They exist; are any of them secure?

Re: OpenClaw privilege escalation vulnerability

#144

Earlier quoted context omitted.

> Digging up the data from example the 135k instances in the open reeks like bullshit, I would suspect several other claims are exaggerated as well. Do you so stringently examine most CVEs? I’ll bet you don’t. Are you a big fan of this project? I’ll bet you are. Do you have any actual data to counter what they said or do you just sort of generally not vibe with it? If so, now would be a great time to break it out whi…

They are pointing out the data provided does not appear to be real. There is no credible link to this 135k number. They do not need to provide a number, as one does not appear to exist.

Well the post was removed so that’s not very promising on their part.

Re: OpenClaw privilege escalation vulnerability

#145

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I don't use this one, but a simpler one, also running on a vps. I communicate via telegram.

I say to it: check my pending tasks on Todoist and see if you can tackle on of those by yourself.

It then finds some bugs in a webapp that I took note. I tell it to go for it, but use a new branch and deploy it on a new url. So it clones the repo, fix it, commit, push, deploy, and test. It just messages me afterwards.

This is possible because it has access to my todoist and github and several other services.

Re: OpenClaw privilege escalation vulnerability

#147

Earlier quoted context omitted.

How is 20% of users getting pwned ”crying wolf” by any reasonable measure? This is a zero authentication admin access vulnerability.

All the numbers you are using appear to be made up by the reddit poster. I say that as they provided no citation to them (for all I know they got them from an AI). I attempted to verify any of the numbers he used and could not. By exaggerating the numbers he is crying wolf.

Well the post was removed so it doesn’t lend a lot of support to their claims.

Re: OpenClaw privilege escalation vulnerability

#148
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

You can't comment like this on Hacker News. The guidelines make it clear we're trying for better than this. https://news.ycombinator.com/newsguidelines.html

We detached this comment from https://news.ycombinator.com/item?id=47629849 and marked it off topic.

Re: OpenClaw privilege escalation vulnerability

#149
post #80

Earlier quoted context omitted.

[flagged]

I'm critical of OpenClaw and even the author to some extent, but I prefer to have nuanced and compartmentalized conversations, on a thread about a specific vulnerability, it's much more productive to talk about the specific vulnerability rather than OpenClaw as a whole. Otherwise we would only have generic OpenClaw conversations and we would only be saying the same thing.

The comment could have been more substantive but it isn't generic or tangential. Discussing a vulnerability ultimately means discussing the failures of process that allowed it to be shipped. Especially with these application-level logic bugs that static analyzers can't generally find, the most productive outcome (after the vulnerability is fixed) is to discuss what process changes we can make to avoid shipping the next vulnerability. I'm sure there's hardening that can be done in OpenClaw but the premise of OpenClaw is to integrate many different services - it has a really large attack surface, only so much can be done to mitigate that, so it's critical to create code review processes that catch these issues.

OpenClaw is probably entering a phase of it's life where prototype-grade YOLO processes (like what the tweet describes) aren't going to cut it anymore. That's not really a criticism, the product's success has over vaulted it's maturity, which is a fortunate problem to have.

Re: OpenClaw privilege escalation vulnerability

#150
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]
Post reply on HN