logoalt Hacker News

mh2266yesterday at 9:37 PM2 repliesview on HN

> “did they patch this RCE,”

no, they documented it

https://docs.openclaw.ai/gateway/security#node-execution-sys...


Replies

g947oyesterday at 10:10 PM

So that's shifting the responsibility to users. And likely many users tools don't understand what those words mean.

All these companies/projects break decades of our security practice and sell you AI browser, AI agent for... I don't know what?

show 1 reply
vulnwrecker5000yesterday at 11:09 PM

yeah fair, but “documented” isn’t really a mitigation... most people are gonna run defaults, so defaults basically are the security model imo

show 1 reply