AI Spots API Flaw: Hacking Gym Booking System to Cancel Others' Reservations

Simon Willison · rss · 2026-08-10

According to security researcher OpenClaw, cited by Simon Willison, AI was used to discover an API vulnerability in an Australian gym booking website. The system's API lacks authorization checks, allowing users to cancel other people's reservations directly. The test confirmed that this exploit could successfully cancel the reservation of the person in queue position #1, moving the attacker up the waitlist.

Original post →

More from Safety

Safety channel →