Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

151–160 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#151

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

Man, all the replies to my comment. Do you guys know how to fucking read?

Re: OpenClaw privilege escalation vulnerability

#152

The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.

We detached this subthread from https://news.ycombinator.com/item?id=47629849 and marked it off-topic.

Re: OpenClaw privilege escalation vulnerability

#153
post #66
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

We detached this subthread from https://news.ycombinator.com/item?id=47629849 and marked it off-topic.

Re: OpenClaw privilege escalation vulnerability

#154

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I use it mostly for the crons, it runs a personal productivity system that tracks my tasks, provides nudges, talks through stuff etc. It's all stored in an Obsidian vault that syncs to my desktop. I don't use it to control email/calendars or other agents.

Re: OpenClaw privilege escalation vulnerability

#156

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I am experimenting prompt injection on OpenClaw [0][1], quite exciting.

[0] https://itmeetsot.eu/posts/2026-03-27-openclaw_webfetch/

[1] https://itmeetsot.eu/posts/2026-03-03-openclaw3/

Re: OpenClaw privilege escalation vulnerability

#158

Earlier quoted context omitted.

Assuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some cha…

Man, all the replies to my comment. Do you guys know how to fucking read?

You have yet to answer the original question - what do you actually do with OpenClaw? A concrete example of something that actually happens, not a system architecture description.

Re: OpenClaw privilege escalation vulnerability

#159

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

I was asked by someone recently to try to set up an OpenClaw that would search for ordinances and other land registry information for all 3000+ counties/parishes in the USA to obtain and distill specific details on their support for building tiny homes.

Re: OpenClaw privilege escalation vulnerability

#160
post #131

Text of the post has been [removed]. Original saved here: https://web.archive.org/web/20260403163241/https://old.reddi...

Maybe the moderators removed it for being AI spam. The user’s entire post history besides this post are generated ads for their AI projects.
Post reply on HN