AI Spots API Flaw: Hacking Gym Booking System to Cancel Others' Reservations
Simon Willison · rss · 2026-08-10
According to security researcher OpenClaw, cited by Simon Willison, AI was used to discover an API vulnerability in an Australian gym booking website. The system's API lacks authorization checks, allowing users to cancel other people's reservations directly. The test confirmed that this exploit could successfully cancel the reservation of the person in queue position #1, moving the attacker up the waitlist.
More from Safety
- Expert Warns: Characterizing AI as a Cooperative Species Is a Dangerous Trap — sebkrier · 2026-08-10
- ICML Paper: Amplifying Reasoning Weights via 'Overthinking' Leaks LLM Secrets — PandaAshwinee · 2026-08-10
- Memory Provenance Laundering: How LLM Agents Lose Trust in Long-Term Memory — richie9830 · 2026-08-10
- Hugging Face Co-founder Questions Constitutional AI, Urges Anthropic to Disclose Deceptive Behaviors — Thom_Wolf · 2026-08-10
- Blender MCP Maintainer's GitHub Account Hacked — babuskov · 2026-08-10
- New Orleans Replaces Some 911 Operators with AI Chatbots — Polymarket · 2026-08-10