Comment on 1-Click RCE to steal your Moltbot data and keysparentComments−mh22667mo“did they patch this RCE,”no, they documented ithttps://docs.openclaw.ai/gateway/security#node-execution-sys...−g947o7moSo that's shifting the responsibility to users. And likely many users tools don't understand what those words mean.All these companies/projects break decades of our security practice and sell you AI browser, AI agent for... I don't know what?−vulnwrecker50007mo"productivity and optimization of your life" i guess? lol−vulnwrecker50007moyeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo−mh22667moI'm not saying that "well we stated that our tool is designed as an RCE exploit" is, uh, better−vulnwrecker50007mohaha fair "we've designed a fully exploitable agent and we can't wait to share it with the world" :')
Comments
no, they documented it
https://docs.openclaw.ai/gateway/security#node-execution-sys...
So that's shifting the responsibility to users. And likely many users tools don't understand what those words mean.
All these companies/projects break decades of our security practice and sell you AI browser, AI agent for... I don't know what?
"productivity and optimization of your life" i guess? lol
yeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo
I'm not saying that "well we stated that our tool is designed as an RCE exploit" is, uh, better
haha fair "we've designed a fully exploitable agent and we can't wait to share it with the world" :')