Switch language한국어
Back to the list

OpenClaw gives users yet another reason to be freaked out about security

TL;DR AI

Key summary

2 min read
  1. OpenClaw has 347,000 stars on GitHub.

  2. It was introduced in November.

  3. Three high-severity vulnerabilities were fixed by security patches.

  4. CVE-2026-33579 lets users with pairing privileges escalate to administrative status; severity rated 8.1–9.8. An attacker with operator.pairing scope can silently approve pairing requests that request operator.admin scope.

  5. Once a pairing is approved, the attacker gains full administrative access to the OpenClaw instance without a secondary exploit; Blink researchers say the practical impact is severe.

Read the original