---
id: 20260811-T0-08
title: "OpenClaw创始人演示攻击健身房预订系统：API无鉴权可取消他人预约"
title_en: "OpenClaw Hacks Gym Booking API, Highlights Missing Auth Checks"
url: https://ai.daily.yangsir.net/daily/20260811-T0-08
issue_date: 2026-08-11
publish_date: 2026-08-10T02:05:16.000Z
category: insight
source_name: "Simon Willison"
source_url: https://simonwillison.net/2026/Aug/10/openclaw/#atom-everything
---

# OpenClaw创始人演示攻击健身房预订系统：API无鉴权可取消他人预约

AI 安全研究员 OpenClaw 在测试一个澳大利亚健身房预订网站时发现，其 API 没有对取消他人预订的操作做任何鉴权。他实际测试了将排队第 4 位用户提升到第 3 位，操作成功。该发现再次引发了关于 AI 代理安全性和 API 设计的讨论。

## English Version

**OpenClaw Hacks Gym Booking API, Highlights Missing Auth Checks**

In a live test against an Australian gym booking site, researcher OpenClaw demonstrated that the API lacked authorization checks on canceling other users' reservations. The test successfully moved a user from position #4 to #3 in the waitlist, sparking fresh debate on AI agent security practices.

---

**来源**：[Simon Willison](https://simonwillison.net/2026/Aug/10/openclaw/#atom-everything)

**详情页**：https://ai.daily.yangsir.net/daily/20260811-T0-08

---

*智语观潮 · Daily — https://ai.daily.yangsir.net/llms.txt*