Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

171–180 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#171
post #153

Earlier quoted context omitted.

We detached this subthread from https://news.ycombinator.com/item?id=47629849 and marked it off-topic.

Why?

It breaks several guidelines:

Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.

Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.

Please don't fulminate. Please don't sneer.

Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.

The guidelines still apply, even if you feel negatively towards a project and its creator. Indeed it's even more important to make the effort to heed the guidelines for topics you feel negatively towards (after all, it's easy to be respectful about things we feel positively towards).

https://news.ycombinator.com/newsguidelines.html

Re: OpenClaw privilege escalation vulnerability

#173
post #2

Earlier quoted context omitted.

[flagged]

Hanlon's Razor https://en.wikipedia.org/wiki/Hanlon%27s_razor

That razor is poorly understood. It’s not malice if it can be explained by stupidity. In this case it’s not explained by stupidity, as the guy who made OpenClaw is very smart. Therefore, it can only be malice.

Re: OpenClaw privilege escalation vulnerability

#174

The Ludditism in this thread, and the linked thread, is shocking.

Is it Ludditism to not want to get PWNed spending $3k a month?

Yes.

All new technology has issues. Figure it out.

Especially if you're spending $3k per month on inference, have the model fix the agent.

I suppose the idea is to wait for someone else to productize it.

Lazy.

Re: OpenClaw privilege escalation vulnerability

#175
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Please don't cross into personal attack. It destroys what this site is for, and you can always make your substantive points without it.

https://news.ycombinator.com/newsguidelines.html

Re: OpenClaw privilege escalation vulnerability

#176
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Please make your substantive points without crossing into personal attack. Your comment would be fine but for the paragraph in the middle where it does that.

https://news.ycombinator.com/newsguidelines.html

Re: OpenClaw privilege escalation vulnerability

#178
post #8

Really? Posting AI generated Reddit post with no sources or anything?

The link mentions the CVE, here's the link https://nvd.nist.gov/vuln/detail/CVE-2026-33579

Thanks! We've changed the top URL to that from https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_..., but I'll put the latter in the toptext.

Re: OpenClaw privilege escalation vulnerability

#179
[stub for offtopicness and general piling-on behavior, which we don't want on this site]

[[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]]

[[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

Re: OpenClaw privilege escalation vulnerability

#180
post #175

Earlier quoted context omitted.

[flagged]

Please don't cross into personal attack. It destroys what this site is for, and you can always make your substantive points without it. https://news.ycombinator.com/newsguidelines.html

Didn‘t know that pointing out a lack of accountability is seen as personal attack.

Who wants the fame must also take the blame.

Especially if they create a dangerous tool.

Post reply on HN