Live data from Hacker News

OpenClaw privilege escalation vulnerability

nvd.nist.gov

81–90 of 306 posts

Re: OpenClaw privilege escalation vulnerability

#81
post #12

OpenClaw has over 400+ security issues and vulnerabilities. [0] Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks? Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone. [0] https://github.com/opencl…

It does not need access to your full machine. It can literally run in a vps.

Most of the people using it probably don't even know what SSH is, let alone using a VPS to maintain a personal bot for them for years with no maintenance. They know Vercel and Supabase. They will run it on their local machine and just keep clicking yes to everything until they get the result they want.

Re: OpenClaw privilege escalation vulnerability

#82

The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.

[flagged]

Re: OpenClaw privilege escalation vulnerability

#83
post #78
post #73

Earlier quoted context omitted.

[flagged]

No? The comment was admittedly ambiguous but if you go to repo it's far clearer: >I use it to give me a weekly digest of what happened in my neighborhood and if there are any public hearings or trash pickups I might want to attend.

that does not seem like something you need an 'autonomous' agent for.

Re: OpenClaw privilege escalation vulnerability

#84

The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.

[flagged]

Aside from "exponentially" being hyperbolic, which part is unsubstantiated?

Re: OpenClaw privilege escalation vulnerability

#85

Honest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...

Agent based chron jobs mostly that work with other agents. It’s really nice if you want to tell your computer to do something repeatedly or in confluence with many other agents in a very simple way. Like check my email for messages from Nadia and send me a notification and turn on all the lights in my driveway when she gets there without having to actually get into the nuts and bolts of implementing it. It’s actually really powerful and probably what Siri should be.

Re: OpenClaw privilege escalation vulnerability

#86
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

Re: OpenClaw privilege escalation vulnerability

#87
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

Guys, OpenClaw is a toy, that's it!

Re: OpenClaw privilege escalation vulnerability

#89
post #66
post #179

[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]

[flagged]

> There used to be a time where people who shipped CVEs took accountability.

I see you haven't heard of Microsoft...

Re: OpenClaw privilege escalation vulnerability

#90

The root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.

[flagged]

This is a vibe based comment. It’s a generic attack with no meat.
Post reply on HN