← ALL NEWS

SIMON WILLISON · 10 Aug 2026

Quoting OpenClaw

This short blog post collection entry shares a quote from OpenClaw regarding a security vulnerability found on an Australian gym booking website. The post was published on Simon Willison’s weblog on August 10, 2026.

The specific finding centers on an application programming interface that lacked any authorization checks for canceling other users' reservations. To test the flaw, OpenClaw successfully canceled a reservation belonging to another person on the waitlist, which immediately advanced the tester's position.

This excerpt highlights a significant security flaw involving unauthorized access and data manipulation on a public booking platform. By capturing this example, the post points to ongoing concerns around API vulnerabilities and digital security testing.

Read the original ↗