11 ms·
OpenClaw privilege escalation vulnerability
https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_running_openclaw_you_probably_got_hacked/ https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_...
https://web.archive.org/web/20260403174514/https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_running_openclaw_you_probably_got_hacked/ https://web.archive.org/web/20260403174514/https://old.reddi...
- throwpoaster 6mo agoThe Ludditism in this thread, and the linked thread, is shocking.
- weakfish 6mo agoIs it Ludditism to not want to get PWNed spending $3k a month?
- throwpoaster 6mo agoYes. All new technology has issues. Figure it out. Especially if you're spending $3k per month on inference, have the model fix the agent. I suppose the idea is to wait for someone else to productize it. Lazy.
- nickthegreek 6mo agoSetting it up that way is a choice a user would have to make. Just set it up on an oauth or budgeted api and not be an idiot. Setup additional guardrails in OC if you think are necessary.
- 8593376393 6mo ago[dead]
- yoyohello13 6mo agoWe need a new word for people who use the word ‘Luddite’ to refer to ‘reasonable concern over the reckless use of new technology’.
- mememememememo 6mo agoYolos?
- gloosx 6mo ago[flagged]
- redoh 6mo ago[flagged]
- sva_ 6mo ago> 4. System grants admin because it never checks if you are authorized to grant admin Shipping at the speed of inference for real.
- deleted 6mo ago[deleted]
- gos9 6mo agoReally? Posting AI generated Reddit post with no sources or anything?
- tgv 6mo agoThe CVE seems to be real.
- hmokiguess 6mo agoThe link mentions the CVE, here's the link https://nvd.nist.gov/vuln/detail/CVE-2026-33579 https://nvd.nist.gov/vuln/detail/CVE-2026-33579
- dijksterhuis 6mo agoif would be good if we could have the submission including this link at the top
- dang 6mo agoThanks! We've changed the top URL to that from https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_running_openclaw_you_probably_got_hacked/ https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_..., but I'll put the latter in the toptext.
- deleted 6mo ago[deleted]
- throwatdem12311 6mo agoThink of all the people that are too ignorant to even understand the basics of any of this that are running OpenClaw. They will be completely unaware and attackers can easily hide their tracks by changing system prompts (among plenty of other things). This is bad.
- fg3fgq 6mo agoWhy is it bad? I think they deserve what's getting to them. And frankly the AI hype needs an ugly episode to simmer things down.
- earnesti 6mo agoI don't think enabling admin on open internet is a default behaviour by any means?
- rvz 6mo agoOpenClaw has over 400+ security issues and vulnerabilities. [0] Why on earth would you install something like that has access to your entire machine, even if it is a separate one which has the potential to scan local networks? Who is even making money out of OpenClaw other than the people attempting to host it? I see little use out of it other than a way to get yourself hacked by anyone. [0] https://github.com/openclaw/openclaw/security https://github.com/openclaw/openclaw/security
- nickthegreek 6mo agoIt does not need access to your full machine. It can literally run in a vps.
- fraywing 6mo agoHow do you think the vibe-coding layman audience is using OpenClaw?
- nickthegreek 6mo agoHostinger vps if youtube is any indication. Also its actually hard for a layman to run this software.
- butlike 6mo ago"All you have to do is run the command `/yolo` to start your instance of OpenClaw." /s
- yoyohello13 6mo agoBased on the hype, a Mac mini.
- rob 6mo agoMost of the people using it probably don't even know what SSH is, let alone using a VPS to maintain a personal bot for them for years with no maintenance. They know Vercel and Supabase. They will run it on their local machine and just keep clicking yes to everything until they get the result they want.
- Simon321 6mo agoOnly if your openclaw instance is publicly exposed on the internet... which is not the case for most people
- causal 6mo agoUntil recently, this was default configuration Edit: Default binding was to 0.0.0.0, and if you were not aware of this and assumed your router was keeping you safe, you probably should not be using OpenClaw. In fact some services may still default to 0.0.0.0: https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/issues/5263 https://github.com/openclaw/openclaw/commit/5643a934799dc523ec2ef18c007e1aa2c386b670 https://github.com/openclaw/openclaw/commit/5643a934799dc523...
- nickthegreek 6mo agoNot true. So many people love to come out of the woodwork on these openclaw posts who have no first hand knowledge of the software. It is stunning.
- charcircuit 6mo agoSince pretty much the beginning it wasn't and the documentation explicitly warned not to make it public, exposing it to the internet. It included information on how you can properly forward the gateway port to your machine without opening it up to the internet.
- earnesti 6mo agoI have used openclaw pretty long but at no point it has proposed doing anything like that.
- quietsegfault 6mo agoIt’s possible, and maybe even trivial, to hit a malicious website that tries to connect to the OpenClaw port on your local machine. A malicious web page runs JavaScript that makes a fetch() or XMLHttpRequest to http://localhost:CLAWPORT — your browser executes that from your machine, so it bypasses your router/firewall entirely. If OpenClaw is listening on localhost with no auth, the browser just connects to it. Same-origin policy doesn’t save you because the request originates from your own machine.
- blharr 6mo ago[flagged]
- throwatdem12311 6mo agoAs if the non-Reddit links aren’t majority AI slop already.
- dgellow 6mo agoFlag then move to the next one
- niwtsol 6mo agoTitle is a bit misleading, no? You have to have openclaw running on an open box. And the post even says "135k open instances" out of 500k running instances? so a bit clickbait-y
- mey 6mo agoMore than 25% of users seems like a pretty accurate "probably".
- peacebeard 6mo agoToday I learned nobody agrees on what the word "probably" means.
- SequoiaHope 6mo agoYa I thought it meant “more probable than not” ie 50+%. Otherwise I would say “you may have been hacked” not “you probably have been hacked”.
- lwansbrough 6mo agoThat is what it means. Unless you're losing an argument on the internet and you need a word to hide behind. ;)
- zephen 6mo agoYou're probably right.
- furyofantares 6mo agoHere's a statement that's about 3x as true then: If you're running OpenClaw, you probably didn't get hacked in the last week.
- DrewADesign 6mo agoYou know you’re getting into zealot territory when people are arguing semantics over the headline pointing to a zero authentication admin access vulnerability CVE that affects a double-digit percentage of users.
- petcat 6mo agoI don't use OpenClaw, but I still run my Claude Code and Codex as limited macOS user accounts and just have a script `become-agent <name> [cmd ...]` that does some sudo stuff to run as the limited user so they don't have any of my environment or directory access, or really any system-level admin access at all. They can use and write to their home directories as usual, which makes things easier to configure since those CLI harnesses really like when $HOME is configured and works as expected. It's a good compromise between running as me and full sandbox-exec. Multi-user Unix-y systems were designed for this kind of stuff since decades ago.
- w10-1 6mo agoYes, if/since that user have no access to your apple id and keychain... Not too much harder is using a VM: With Apple's open-source container tool, you can spin up a linux container vm in ~100ms. (No docker root) With Apple virtualization framework, you can run macOS in a VM (with a separate apple id).
- petcat 6mo ago> Yes, if/since that user have no access to your apple id and keychain... Right, these are system accounts. They don't have access to anything except their own home folder and whatever I put in their .bashrc. `sudo` is a pretty easy sandbox by itself and lets me manage their home folders, shell, and environment easily just with the typical Unix-isms. No need for mounting VM disks, persisting disk images, etc. I don't need virtualization to let Claude Code run. I just let it run as a "claude" user.
- txprog 6mo agoThis is why kernel-level sandboxing matters. I use a sandbox name greywall that enforce filesystem/network isolation at the syscall level (Landlock + Seccomp + eBPF on linux, sandbox-exec on mac). I do disagree about unix system were designed for this kind of stuff. Unix was not designed for an agent to act like you and take decision for you...
- throwatdem12311 6mo ago
- Leomuck 6mo agoWell, such things were to be expected. It's easy to bash on all the people who haven't gotten the necessary IT understanding of securing such things. Of course, it's uber-dumb to run an unprotected instance. But at the same time, it's also quite cool that so many people can do interesting IT stuff now. I'm thinking basically it's a trade-off. Be able to do great stuff, live with the consequences of doing that without proper training. Like repairing your car yourself. You might have fun doing it, it might get you somewhere, but you have to accept that if you have no idea about cars, you just introduced a pretty big risk into your life (say if you replaced the brakes or something). But yea, security, privacy, fighting climate change, all very much on the decline - humans doing cool things, ignoring important things - we'll have to live with the consequences.
- paulhebert 6mo agoGonna be honest. I'd rather fight climate change than have people run LLMs unsecured
- Xunjin 6mo agoYeah... The bill is already being paid. I wonder how the life quality of my nephew (and other children) of 5 years old today will be in the near future..
- shaky-carrousel 6mo agoDecades, decades, telling us to save energy. Removing screensavers, replacing lightbulbs with ugly CFL first and color distorted LED lamps after. Trying to save energy to save the planet. And now, all of that to the toilet because some morons decided to play with talking robots. Yesterday I did care. Today? Not so much. Welcome climate change, we fully deserve it.
- tdeck 6mo agoYou forgot cryptocurrency. At least some of this LLM stuff is genuinely useful.
- sunaookami 6mo agoHonest question: What do people actually USE OpenClaw for? The most common usage seems to be "it reads your emails!", that's the exact opposite of "exciting"...
- browningstreet 6mo ago[flagged]
- freedomben 6mo agoyeah I don't normally say "read previous HN articles" but it has been asked at least once in every article here.
- sunaookami 6mo agoObviously I already searched the web (not specifically HN I must admit) and there were always incredibly generic non-answers that ultimately say nothing (and they assume you have 3000$ per month or 2000 Mac Minis on your desk (hyperbole)).
- ziml77 6mo agoIncredibly, one of the responses you got already is exactly one of those replies that says nothing. There's a whole bunch of words that don't actually answer the question.
- emp17344 6mo agoI think you’ve got your answer, then. If nobody can tell you what it’s really used for, it likely doesn’t have any real use cases.
- _doctor_love 6mo agoAssuming you're asking in good faith, IMHO the deeper story around OpenClaw is that it's the core piece of a larger pattern. The way I'm seeing folks responsibly use OpenClaw is to install it as a well-regulated governor driving other agents and other tools. It is effectively the big brain orchestrating a larger system. So for instance, you could have an OpenClaw jail where you-the-human talk to OpenClaw via some channel, and then that directs OpenClaw to put lower-level agents to work. In some sense it's a bit like Dwarf Fortress or the old Dungeon Keeper game. You declare what you want to have happen and then the imps run off and do it. [EDIT: I truly down understand sometimes why people downvote things. If you don't like what I'm saying, at least reply with some kind of argument.]
- steipete 6mo agoOpenClaw creator here. This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance." The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerScopes`, and the core logic failed open when that parameter was missing. So the strongest confirmed exploit path was: a client that ALREADY HAD GATEWAY ACCESS and enough permission to send commands could use `chat.send` with `/pair approve latest` to approve a pending device request asking for broader scopes, including `operator.admin`. In other words: a scope-ceiling bypass from pairing/write-level access to admin. This was not primarily a Telegram-specific or message-provider-specific bug. The bug lived in the shared plugin command handler, so any already-authorized command sender that could reach `/pair approve` could hit it. For Telegram specifically, the default DM policy blocks unknown outsiders before command execution, so this was not "message the bot once and get admin." But an already-authorized Telegram sender could still reach the vulnerable path. The practical risk for this was very low, especially if OpenClaw is used as single-user personal assistant. We're working hard to harden the codebase with folks from Nvidia, ByteDance, Tencent and OpenAI.
- hyperlambda 6mo ago[flagged]
- machinecontrol 6mo agoThe root issue is that OpenClaw is 500K+ lines of vibe coded bloat that's impossible to reason about or understand. Too much focus on shipping features, not enough attention to stability and security. As the code base grows exponentially, so does the security vulnerability surface.
- dyauspitr 6mo ago[flagged]
- williamstein 6mo agoThe current OpenClaw GitHub repo [1] contains 2.1 million lines of code, according to cloc, with 1.6M being typescript. It also has almost 26K commits. [1] https://github.com/openclaw/openclaw https://github.com/openclaw/openclaw
- deleted 6mo ago[deleted]
- asddubs 6mo agowow, this repo seems to get something like 100 commits an hour based on just scrolling through the recent ones.
- kube-system 6mo agoIf someone could forward the SSH port from my VPS to access my instance, I already had bigger problems.
- n1tro_lab 6mo ago[flagged]
- jeremie_strand 6mo ago[dead]
- reenorap 6mo agoThe threads on that /r/sysadmin post sound exactly like every sysadmin I've ever worked with in my career.
- rossjudson 6mo agoWith respect...Security through obscurity is dead. We are approaching the point where only formally verified (for security) systems can be trusted. Every possible attack will be attempted. Every opening will be exploited, and every useful combination of those exploits will be done. LLMs are patient, tireless, capable of rigorous opsec, and effectively infinite in number.
- Meneth 6mo agoText of the post has been [removed]. Original saved here: https://web.archive.org/web/20260403163241/https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_running_openclaw_you_probably_got_hacked/ https://web.archive.org/web/20260403163241/https://old.reddi...
- frenchtoast8 6mo agoMaybe the moderators removed it for being AI spam. The user’s entire post history besides this post are generated ads for their AI projects.
- dang 6mo agoThanks, we'll put that link in the toptext as well.
- RodMiller 6mo ago[dead]
- roangeller 6mo ago[flagged]
- dang 6mo ago[stub for offtopicness and general piling-on behavior, which we don't want on this site] [[attacking project creators when they show up to discuss their work is particularly harmful; please don't ever do that here]] [[[if you posted any of these, we'd appreciate it if you'd please review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and stick to the rules from now on]]]
- bigstrat2003 6mo agoIf you're running OpenClaw, you already threw security and reliability out the window by running LLMs on the command line. It's a bit late to start worrying now.
- deadbabe 6mo ago[flagged]
- EA-3167 6mo agoIn this case I'd say that it was made not to enable that, but in total disregard of its realistic uses and risks. In a sense this is less... deliberate poisoning, and more doing a bad job cutting heroin with fentanyl for distribution. Yeah the result is the same, but the cause is negligence to the point of parody rather than outright malice.
- throwatdem12311 6mo agoSome people are so stupid it is indistinguishable from evil.
- cactusplant7374 6mo agoWhat reason would Steinberger have for doing that? It was his hobby project.
- asdff 6mo agoHe doesn't need a reason. He could have been captured by intelligence after the fact.
- ritcgab 6mo agoIsn't OpenClaw itself a privilege escalation?
- vntok 6mo agoHow could it be? Everything it does it does with its caller's privilege. It's not hacking your machine. Run it as root it will have root caps, run it as ritcgab it will have ritcgab's caps. Same as every other program.
- jeremie_strand 6mo ago[dead]
- vasco 6mo ago> We're working hard to harden the codebase with folks from Nvidia, ByteDance, Tencent and OpenAI. But coding is solved? Why do you need those guys if all they do is use claude code? Just have it solve it overnight. You forgot to prompt "make it secure pls"?
- rolisz 6mo agoCoding is solved, but problems with code is not yet solved.
- parchley 6mo agoSurely you must realise the absurdity of that statement
- prerok 6mo agoI am pretty sure they were being sarcastic.
- deleted 6mo ago[deleted]
- tdeck 6mo agoI think I'm pretty good at cooking, but still working on the part where it tastes like food and doesn't make you violently ill.
- ex-aws-dude 6mo agoThe Rubik’s cube is solved but the problem with some sides being multiple colors is not solved
- tdeck 6mo agoThey didn't say the "folks" from those companies were engineers! Maybe it's a group of PMs from Nvidia, ByteDance, Tencent and OpenAI that are working to harden the codebase.
- chatmasta 6mo agoI’m surprised people are still using OpenClaw. I assumed they’d have switched to Nanoclaw or Nemoclaw. Is OpenClaw just that much better, or is it all inertia? (I’ve never used any of them.)
- Flere-Imsaho 6mo agoI'm using Hermes. The same applies to all agents, don't give it free reign over all your stuff. Run it within a sandbox. https://github.com/nousresearch/hermes-agent https://github.com/nousresearch/hermes-agent
- claude_sh_1959 6mo agowhich one is recommended? (on machine - oss)
- huflungdung 6mo ago[dead]
- jbergqvist 6mo agoNemoClaw is an OpenClaw security wrapper, not a replacement
- awestroke 6mo agoIt's shit, but most people don't know better
- tao_oat 6mo agoRelevant: https://days-since-openclaw-cve.com/ https://days-since-openclaw-cve.com/ Currently we're at 1.8 CVEs per day since OpenClaw launched!
- mattstir 6mo agoThat is genuinely horrifying. I wonder what the stats are for an average "artisan, hand-typed" project would be if it got as much attention as OpenClaw has. But 1.8 CVEs a day should scare any rational people away from the software... right? Surely?
- maccard 6mo agoI’m not an openclaw user or a vibe coder but - the use case of OpenClaw is “give me access to all of your data, programs and information, and I will make decisions and do stuff without asking you permission”. It’s the MO of the project. Even if it was perfectly designed, I think it would have more RCEs by the fact that the Venn diagram of use of the app and high risk areas are a perfect circle
- earnesti 6mo agoI'm OpenClaw user and I never would do that. You can do with OpenClaw that, but it is definitely not the only use case, and I would argue that not even the one that makes sense overall. Most people want to be careful which decisions you want to outsource and which not, and you can direct the AI to work however you prefer. Personally I have developed some projects with OpenClaw, and it does have very limited permissions.
- BeetleB 6mo ago> the use case of OpenClaw is “give me access to all of your data, programs and information, and I will make decisions and do stuff without asking you permission”. It’s the MO of the project. You say that, but you also say > I’m not an openclaw user Your first statement makes the second one rather obvious. As I said some weeks ago, I've given up pointing out on HN: "Well, you could just not give it your data" only to be repeatedly told (by non-users) that the whole point is to give it all your data. And the myth continues...
- throwatdem12311 6mo agoSteinberger has a vested interest in protecting his, and OpenAIs reputation from the ramifications of serious in-the-wild exploits like this. Or inviting any legal or regulatory scrutiny. They don’t even read the code in any serious capacity so excuse me for not taking any assessment of the situation from him too seriously. Might as well just ask Claude Code to assess it yourself. Welcome to the world vibe coding created. The fun is only just beginning.
- lnenad 6mo ago> Welcome to the world vibe coding created. Hard disagree. Vibe coding isn't responsible for people not doing the slightest due diligence when running this (pardon my French) shit. You can vibe code stuff and keep it at a much higher quality. And you can check who did the vibecoding and how they approached it, so the burden also falls on the person running the stuff to understand what they're running. This isn't an enterprise level application that has a full team behind it that had an issue. This is a pandora's box vibecoded overnight for fun, full of stuff we don't even know about, that was opened the moment you touched it with a stick.
- DrewADesign 6mo agoIn my experience, most garden variety security problems stem from a) the developer not understanding the implications of something (maybe because they’re new, or operating outside of their usual domain,) or b) the developer not paying close enough attention to realize they did something they know is stupid. We’re only human. Vibe coding obviously doesn’t make something insecure, per se, but saying it doesn’t reduce the attention paid to any given line of code, or encourage less knowledgeable people to write code, seems pretty dubious to me. The Claude Code team is clearly competent and professional, yet they accidentally published the proprietary source code for one of the world’s hottest products. That’s like a Bank manager walking away with the keys in the door and alarm disarmed. When’s the last time you heard of a human team of developers doing that? Again, I’m not saying that vibe coding necessarily creates unsafe code, but I don’t see how anyone could say vibe coding was devoid of security implications. I think this is an organizational/logistical problem that we’ll figure out at some point, but in think it’s going to be more of a C buffer overflow ‘figured out’ that never really goes away.
- acedTrex 6mo agoWho cares man, the sloppiest and shittiest software ever written has yet another CVE. This is not worth discussing.
- jeremie_strand 6mo ago[dead]
- eager_learner 6mo ago[flagged]
- dfir-lab 6mo ago[flagged]
- plasticeagle 6mo agoOpen Claw cannot be made "secure" by any normal definition of the word. Unless I'm very much mistaken, fundamentally it's a tool that lets LLMs do stuff. So you take the output of an LLM, which is obviously impossibly to guarantee correct, and use that to choose a tool and execute it. Like, send an email or whatever. And you take the input for that LLM not only from prompts, and various files, but also your system and random stuff you download from the internet. I am telling you people, this is lunacy. No good can come of this.
- Serberus 6mo ago[dead]