{"data":{"id":"9fe375d4-9585-48f9-bde5-ac523d2c0e73","title":"Quoting OpenClaw (running Opus 4.6)","summary":"A security researcher using OpenClaw (an AI tool running Opus 4.6) discovered a critical vulnerability in an Australian gym-booking website where the API (application programming interface, the system that lets software communicate) lacks authorization checks (verification that a user is allowed to perform an action) on canceling reservations, allowing anyone to cancel other users' bookings and manipulate their waitlist positions.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://simonwillison.net/2026/Aug/10/openclaw/#atom-everything","publishedAt":"2026-08-10T02:05:16.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["OpenClaw","Anthropic","Claude","Opus 4.6","OpenAI","Hugging Face"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-10T02:05:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.65,"researchCategory":null,"atlasIds":null}}