Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

161–170 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#161

Earlier quoted context omitted.

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

Man, all the replies to my comment. Do you guys know how to fucking read?

Name 2 things you actually do with OpenClaw. And don't swear in your response.

Re: OpenClaw privilege escalation vulnerability

#162

OpenClaw creator here. This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance." The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerS…

Can you speak a little bit more to the stats in the OP? * 135k+ OpenClaw instances are publicly exposed * 63% of those run zero authentication. Meaning the "low privilege required" in the CVE = literally anyone on the internet can request pairing access and start the exploit chain Is this accurate? This is definitely a very different picture then the one you paint

[deleted]

Re: OpenClaw privilege escalation vulnerability

#163

Earlier quoted context omitted.

[flagged]

Why don't you try it yourself instead of making uninformed claims

Why would I do that? I am entirely good using LLMs like Claude building tools for me. There's no use case for OpenClawthat I am aware of can replace of what I have/need.

I think it makes my point strong, people who uses OpenClaw, might be lazy on how to do things properly with LLMs.

Re: OpenClaw privilege escalation vulnerability

#164
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

[dead]

Re: OpenClaw privilege escalation vulnerability

#165
post #47
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

If you considered using it in the first place, reports of security vulnerabilities wouldn't concern you.

Re: OpenClaw privilege escalation vulnerability

#166

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I am experimenting prompt injection on OpenClaw [0][1], quite exciting. [0] https://itmeetsot.eu/posts/2026-03-27-openclaw_webfetch/ [1] https://itmeetsot.eu/posts/2026-03-03-openclaw3/

Awesome and very interesting posts, thanks for sharing! Always reminds me of the "lethal trifecta": https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

Re: OpenClaw privilege escalation vulnerability

#169

OpenClaw creator here. This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance." The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerS…

> We're working hard to harden the codebase with folks from Nvidia, ByteDance, Tencent and OpenAI.

What exactly does this mean? You have contracts with these companies? People who work for them contributed sometimes in the past to openclaw repository?

Re: OpenClaw privilege escalation vulnerability

#170
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[dead]
Post reply on HN