Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

281–290 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#281

Earlier quoted context omitted.

Awesome and very interesting posts, thanks for sharing! Always reminds me of the "lethal trifecta": https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

You're welcome! My main takeaway message is: models (even opus4.6) do not follow security "instructions" reliably. In OpenClaw, they added security warnings, tags, random IDs... None of these countermeasures work reliably. Even sandboxing can be escaped (not in the classical sense using vulnerabilities, but using multi-layered prompt injection payload with natural language only)[0]. As soon as untrusted content is in…

What do you think about CaMeL and similar approaches?

https://simonwillison.net/2025/Apr/11/camel/

Re: OpenClaw privilege escalation vulnerability

#282
post #270

Earlier quoted context omitted.

I agree—it looks like the OP didn't provide any sources for these numbers either. That's why I would have hoped that the original maintainer had a better set of metrics to dispute them. It doesn't seem like he does though :(

Those numbers aren't in the CVE. You introduced them, attributed them to a source that doesn't contain them, and now you're disclaiming them. Where did they come from, and what was the goal of sharing them?

The numbers were in the post when I clicked through and when I made the comment. It looks like the HN moderators have since changed the link for the post to go to the CVE entry. However, my comment was about the reddit thread, not the CVE entry.

Re: OpenClaw privilege escalation vulnerability

#283
post #266

Steinberger has a vested interest in protecting his, and OpenAIs reputation from the ramifications of serious in-the-wild exploits like this. Or inviting any legal or regulatory scrutiny. They don’t even read the code in any serious capacity so excuse me for not taking any assessment of the situation from him too seriously. Might as well just ask Claude Code to assess it yourself. Welcome to the world vibe coding cre…

> Welcome to the world vibe coding created. Hard disagree. Vibe coding isn't responsible for people not doing the slightest due diligence when running this (pardon my French) shit. You can vibe code stuff and keep it at a much higher quality. And you can check who did the vibecoding and how they approached it, so the burden also falls on the person running the stuff to understand what they're running. This isn't an e…

Vibe coding means you don’t (or can’t) read the code. It does not mean anything an agent writes is vibe coded.. If you’re reviewing the code after the agent writes it, you aren’t vibe coding.

Steinberger has said he doesn’t look at (most) the code.

Re: OpenClaw privilege escalation vulnerability

#284
post #152

Earlier quoted context omitted.

We detached this subthread from https://news.ycombinator.com/item?id=47629849 and marked it off-topic.

I can't really think of a more on topic comment. The thread is about a security issue and the comment is about the quality of the codebase.

The comment is a generic vent about the project’s codebase and development approach, not an effort to engage in curious conversation about this vulnerability. Also, I consider it to be in breach of the guidelines about fulmination, swipes/sneers, and curmudgeonliness.

Re: OpenClaw privilege escalation vulnerability

#285
post #171

Earlier quoted context omitted.

It breaks several guidelines: Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes. Comments should get more thoughtful and substantive, not less, as a topic gets more divisive. Please don't fulminate. Please don't sneer. Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something. The guidelines still apply, even if you feel nega…

Thanks for explaining, is this mostly about replying directly to the person involved in the project? Compared to e.g. a comment in a thread about OpenClaw without replying directly to the creator? Just trying to figure out where the line is, I do think snark is a valid form of criticism sometimes but it's your house after all.

That comment would be a guidelines breach on HN, whether or not it was in reply to the project creator. It gives off just the kind of negativity that HN has always aimed to avoid. Even if we don't always succeed in avoiding it, the guidelines represent an ideal that we work to uphold every day.

> Just trying to figure out where the line is

It's not really about a line, it's about the qualitative style of discussion we’re here for. HN is for people who like to build things and work on interesting new projects, and have curious conversations about what they're building. Projects that are new and built in different ways than what has come before will always be easy to criticise from a position of conformity to historical conventions, but if we all thought that way, nothing new would ever be built.

> I do think snark is a valid form of criticism sometimes

Not on HN. Thoughtful criticism is fine, and the very first two words of the “In Comments” section of the guidelines are “be kind”.

> but it's your house after all

That's not how we think about it. We’re custodians of this place and our role is to keep it a healthy place for discussion among intellectually curious hackers. It takes daily work and effort to uphold the guidelines and keep the standards up so that it doesn’t become the hellscape of negativity that it's often stereotyped as being.

Re: OpenClaw privilege escalation vulnerability

#286

Think of all the people that are too ignorant to even understand the basics of any of this that are running OpenClaw. They will be completely unaware and attackers can easily hide their tracks by changing system prompts (among plenty of other things). This is bad.

Why is it bad? I think they deserve what's getting to them. And frankly the AI hype needs an ugly episode to simmer things down.

Re: OpenClaw privilege escalation vulnerability

#287
post #277

Earlier quoted context omitted.

In my experience, most garden variety security problems stem from a) the developer not understanding the implications of something (maybe because they’re new, or operating outside of their usual domain,) or b) the developer not paying close enough attention to realize they did something they know is stupid. We’re only human. Vibe coding obviously doesn’t make something insecure , per se, but saying it doesn’t reduce…

Very reasonable take, I agree 100%. But I don't you're putting any responsibility with users of the such very vibe coded apps. OpenClaw was primarily marketed towards devs and people in touch with IT. They should know better.

Sure. I reckon blaming the system for the intentional actions of a few is a great way to avoid individual accountability. Conversely, blaming many individuals for fundamental systemic or leadership problems is a great way to avoid accountability for leaders and systemic beneficiaries. It’s not rational to exclude either.

I’m also not sure that the distinction of dev makes much of a difference in this space because chatbot marketing works pretty damn hard to imply everybody is a prompt away from being a developer. How are those people going to know that they aren’t even qualified to make any given technical decision, let alone evaluate the output of a confident chatbot that’s magically writing programs for them?

Re: OpenClaw privilege escalation vulnerability

#288

Earlier quoted context omitted.

You know you’re getting into zealot territory when people are arguing semantics over the headline pointing to a zero authentication admin access vulnerability CVE that affects a double-digit percentage of users .

I mean... the reddit OP's comments are obviously AI-generated. It's quite obvious who is being 'zealot" here.

> It's quite obvious who is being 'zealot" here.

Nooope. Reread the thread from my comment up: they were arguing about whether that percentage of users warranted saying ‘probably’ in the headline. Nobody was even questioning the numbers at that point. Just people taking it at face value, getting defensive, and trying to minimize what it said.

Re: OpenClaw privilege escalation vulnerability

#289

Earlier quoted context omitted.

That is genuinely horrifying. I wonder what the stats are for an average "artisan, hand-typed" project would be if it got as much attention as OpenClaw has. But 1.8 CVEs a day should scare any rational people away from the software... right? Surely?

I’m not an openclaw user or a vibe coder but - the use case of OpenClaw is “give me access to all of your data, programs and information, and I will make decisions and do stuff without asking you permission”. It’s the MO of the project. Even if it was perfectly designed, I think it would have more RCEs by the fact that the Venn diagram of use of the app and high risk areas are a perfect circle

> the use case of OpenClaw is “give me access to all of your data, programs and information, and I will make decisions and do stuff without asking you permission”. It’s the MO of the project.

You say that, but you also say

> I’m not an openclaw user

Your first statement makes the second one rather obvious.

As I said some weeks ago, I've given up pointing out on HN: "Well, you could just not give it your data" only to be repeatedly told (by non-users) that the whole point is to give it all your data.

And the myth continues...

Re: OpenClaw privilege escalation vulnerability

#290
post #74
post #64

Earlier quoted context omitted.

I've only been playing with it recently ... I have mine scraping for SF city meetings that I can attend and public comment to advocate for more housing etc ( https://github.com/sgillen/sf-civic-digest ). It also have mine automatically grabs a spot at my gym when spots are released because I always forget. I'm just playing with it, it's been fun! It's all on a VM in the cloud and I assume it could get pwned at any ti…

>It also have mine automatically grabs a spot at my gym when spots are released because I always forget. seems far more efficient/reliable to get codex/claude code to write and set up a bot that does this.

> seems far more efficient/reliable to get codex/claude code to write and set up a bot that does this.

I think Simon Willison said it best some weeks ago: He's capable of writing a bot like this - both before and after LLMs came on the scene. However, the reality is he never wrote one, despite wanting to many times.

Yet in just 2-3 weeks of using OpenClaw[1], I did this a few times.

Recall a year or so ago in the early days of vibe coding when people kept saying "I don't need AI to write code. It does a crap job and I can do it myself. Who needs LLMs to do it?" - You'd get lots of people countering with "Oh, in a few weeks I've written lots of automations that I'd been thinking about for months/years - that I likely would never have written without AI coding tools".

The key is the lower barrier to producing something. OpenClaw is to using CC to write that bot as using CC was to writing code by hand. I can be doing work, shopping, etc and when an idea pops into my head, I casually send a note to my Claw instance (voice or text) asking it to look into it or try making it. It doesn't do a great job, but the expectations of success are similarly low. But when it does do precisely what you need it to: Oh boy, you're happy that it saved you time, etc.

[1] I no longer run it, for very boring reasons.

Post reply on HN