{"id":13405,"date":"2026-04-04T07:17:15","date_gmt":"2026-04-04T07:17:15","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=13405"},"modified":"2026-04-04T07:17:15","modified_gmt":"2026-04-04T07:17:15","slug":"openclaw-provides-customers-but-one-more-reason-to-be-freaked-out-about-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=13405","title":{"rendered":"OpenClaw provides customers but one more reason to be freaked out about safety"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/02\/bluecrayfish-1152x648.jpg\" \/><\/p>\n<p>For greater than a month, safety practitioners have been warning concerning the perils of utilizing OpenClaw, the viral AI agentic instrument that has taken the event group by storm. A lately fastened vulnerability offers an object lesson for why.<\/p>\n<p>OpenClaw, which was launched in November and now boasts <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/openclaw\/openclaw\">347,000 stars<\/a> on Github, by design takes management of a person\u2019s pc and interacts with different apps and platforms to help with a number of duties, together with organizing recordsdata, doing analysis, and purchasing on-line. To be helpful, it wants entry\u2014and many it\u2014to as many assets as doable. Telegram, Discord, Slack, native and shared community recordsdata, accounts, and logged in classes are solely a number of the supposed assets. As soon as the entry is given, OpenClaw is designed to behave exactly because the person would, with the identical broad permissions and capabilities.<\/p>\n<h2>Extreme influence<\/h2>\n<p>Earlier this week, OpenClaw builders launched safety patches for 3 high-severity vulnerabilities. The severity ranking of 1 particularly, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2026-33579\/\">CVE-2026-33579<\/a>, is rated from 8.1 to 9.8 out of a doable 10 relying on the metric used\u2014and for good cause. It permits anybody with pairing privileges (the lowest-level permission) to achieve administrative standing. With that, the attacker has management of no matter assets the OpenClaw occasion does.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/04\/heres-why-its-prudent-for-openclaw-users-to-assume-compromise\/\">Learn full article<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2026\/04\/heres-why-its-prudent-for-openclaw-users-to-assume-compromise\/#comments\">Feedback<\/a><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>For greater than a month, safety practitioners have been warning concerning the perils of utilizing OpenClaw, the viral AI agentic instrument that has taken the event group by storm. A lately fastened vulnerability offers an object lesson for why. OpenClaw, which was launched in November and now boasts 347,000 stars on Github, by design takes [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":13407,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[8510,7831,7584,211,342],"class_list":["post-13405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","tag-freaked","tag-openclaw","tag-reason","tag-security","tag-users"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13405"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13405\/revisions"}],"predecessor-version":[{"id":13406,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13405\/revisions\/13406"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/13407"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69c6f7b5190636d50e9f6768. Config Timestamp: 2026-03-27 21:33:41 UTC, Cached Timestamp: 2026-04-08 11:29:48 UTC -->