Elektrine lite

← Feed

@Viss@mastodon.social

Post #1253017

2026-04-03 18:35 UTC

@dangoodin so this is a privesc bug. it suggests that a lower privileged user has the ability to pair new stuff to the bot. but most people dont appear to really be using that functionality? most bots are 1:1 in terms of ownership - one bot to one person. but this bug can be used by one existing paired channel (email, telgram, discord, twitter, whatever) to create a new one. so its plausible that an attacker could just dm the owner the right way to pair something THEY control

Replies (2)

  • @Viss@mastodon.social 2026-04-03 18:36

    @dangoodin and this is before even getting into the fact that there are hundreds of thousands of these bots exposed to the internet already, many with zero auth, so you could just take the bot over that way directly, or use the pairing command to pair something you control to the bot so you're not using its web interface to drive it around.

    Open ##1253018

  • @saraislet@infosec.exchange 2026-04-03 19:22

    @Viss @dangoodin years ago there was a vulnerability in which credentials (OAuth tokens IIRC) were exposed in plaintext in every API message sent from a Slack API to another SaaS API I've seen similar patterns in other situations, and I see confused deputy issues regularly (and I imagine increasingly frequently with agentic attack surfaces) Seems like a ripe landscape to take advantage of privesc "OpenClaw" is a good name because I imagine it scuttling sideways to move laterally between allll the things (with a *cough* paring knife, of course)

    Open ##1253022