T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:105- Finding
Unrestricted Search Across Sensitive Historical Session Logs
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–21, 105–110, and 120–125
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code
markdown Session logs live under the active state directory: `$OPENCLAW_STATE_DIR/agents/<agentId>/sessions/` (default: `~/.openclaw/agents/<agentId>/sessions/`). Use the `agent=<id>` value from the system prompt Runtime line. - **`sessions.json`** - Index mapping session keys to session IDs - **`<session-id>.jsonl`** - Full conversation transcript per sessionbash AGENT_ID="<agentId>" SESSION_DIR="${OPENCLAW_STATE_DIR:-$HOME/.openclaw}/agents/$AGENT_ID/sessions" rg -l "phrase" "$SESSION_DIR"/*.jsonlbash AGENT_ID="<agentId>" SESSION_DIR="${OPENCLAW_STATE_DIR:-$HOME/.openclaw}/agents/$AGENT_ID/sessions" jq -r 'select(.type=="message") | .message.content[]? | select(.type=="text") | .text' "$SESSION_DIR"/<id>.jsonl | rg 'keyword'Technical Analysis
The skill instructs the agent to derive the session-storage path from runtime information and search complete historical transcript files. In particular, the documented command at lines 105–110 searches every JSONL transcript belonging to the selected agent rather than limiting access to the conversation explicitly referenced by the user.
Session transcripts can contain private user messages, assistant responses, tool results, personal information, credentials accidentally included in conversations, and context from unrelated providers or sessions. The skill does not require:
- Explicit authorization before reading historical logs.
- Restriction to a specifically identified session.
- Validation that the current requester owns the selected historical session.
- Redaction of secrets or personal information.
- Exclusion of tool results and unrelated provider conversations.
- Confirm ...[truncated 1726 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation before accessing any historical session transcript.
- Default to the single session explicitly identified by the requester; do not search
*.jsonlunless the requester separately authorizes a global search. - Verify that the requester is authorized to access the target session, especially where one agent handles multiple users or providers.
- Resolve session identifiers through an access-controlled index rather than accepting arbitrary agent or session identifiers.
- Restrict paths to the canonical session directory and reject traversal, symlinks, or paths outside the expected agent scope.
- Extract only the minimum fields necessary and exclude tool results, hidden reasoning, metadata, and unrelated messages by default.
- Redact credentials, API keys, authentication tokens, personal information, and other sensitive values before placing excerpts in the active conversation.
- Present file names or match counts first and request confirmation before displaying transcript contents.
- Record auditable metadata for historical-log access, including the requesting session, target session, reason, and files read.
- Document that broad cross-session searches are prohibited unless they are necessary, explicitly authorized, and limited to the requesting user's sessions.
