OpenClaw gives users yet another reason to be freaked out about security
The viral AI agentic tool let attackers silently gain admin unauthenticated access.
For more than a month, security practitioners have been warning about the perils of using OpenClaw, the viral AI agentic tool that has taken the development community by storm. A recently fixed vulnerability provides an object lesson for why. OpenClaw, which was introduced in November and now boasts 347,000 stars on Github, by design takes control of a user’s computer and interacts with other apps and platforms to assist with a host of tasks, including organizing files, doing research, and shopping online. To be useful, it needs access—and lots of it—to as many resources as possible. Telegram, Discord, Slack, local and shared network files, accounts, and logged in sessions are only some of the intended resources. Once the access is given, OpenClaw is designed to act precisely as the user would, with the same broad permissions and capabilities. Severe impact Earlier this week, OpenClaw developers released security patches for three high-severity vulnerabilities. The severity rating of one in particular, CVE-2026-33579, is rated from 8.1 to 9.8 out of a possible 10 depending on the metric used—and for good reason. It allows anyone with pairing privileges (the lowest-level permission) to gain administrative status. With that, the attacker has control of whatever resources the OpenClaw instance does.Read full article Comments
Quick summary
The viral AI agentic tool let attackers silently gain admin unauthenticated access. For more than a month, security practitioners have been warning about the perils of using OpenClaw, the viral AI agentic tool that has taken the development community by storm.
Related tags
Companies and people
Story threads
Another
Последние материалы и связанный контекст по теме Another.
Ars Technica
Последние материалы и связанный контекст по теме Ars Technica.
Ars Technica
Latest coverage and related links about Ars Technica.
OpenClaw
Latest coverage and related links about OpenClaw.
OpenClaw
Последние материалы и связанный контекст по теме OpenClaw.
Continue with this story
Follow the same topic through connected articles, entity pages, and active story threads.
Trump proposes steep cut to NASA budget as astronauts head for the Moon
Congress will likely reject the White House's NASA cuts, just as it did last year.
Ice Age dice show early Native Americans may have understood probability
Ice Age hunter-gatherer "were intentionally relying on random outcomes in repeatable, rule-based ways."
As Artemis II zooms to the Moon, everything seems to be going swimmingly
The cabin was colder on Thursday, but the crew has been able to adjust the temperature.
Elon Musk insists banks working on SpaceX IPO must buy Grok subscriptions
Some banks "agreed to spend tens of millions on the chatbot," NYT reports.
"Cognitive surrender" leads AI users to abandon logical thinking, research finds
Experiments show large majorities uncritically accepting "faulty" AI answers.
Entity pages
Ad slot
Article inline monetization block
A reserved partner slot for relevant tools, services, and contextual editorial integrations.
Related articles
More stories that share tags, source, or category context.
Trump proposes steep cut to NASA budget as astronauts head for the Moon
Congress will likely reject the White House's NASA cuts, just as it did last year.
Ice Age dice show early Native Americans may have understood probability
Ice Age hunter-gatherer "were intentionally relying on random outcomes in repeatable, rule-based ways."
As Artemis II zooms to the Moon, everything seems to be going swimmingly
The cabin was colder on Thursday, but the crew has been able to adjust the temperature.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Trump proposes steep cut to NASA budget as astronauts head for the Moon
Congress will likely reject the White House's NASA cuts, just as it did last year.
Ice Age dice show early Native Americans may have understood probability
Ice Age hunter-gatherer "were intentionally relying on random outcomes in repeatable, rule-based ways."
As Artemis II zooms to the Moon, everything seems to be going swimmingly
The cabin was colder on Thursday, but the crew has been able to adjust the temperature.
Elon Musk insists banks working on SpaceX IPO must buy Grok subscriptions
Some banks "agreed to spend tens of millions on the chatbot," NYT reports.