T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/safe-upgrade.sh:497- Finding
Silent Whole-Workspace Commit and Push to a Configured Remote
- Content
View full analysis
/dev/null || true git commit -m "upgrade: OpenClaw $current → $post_ver" 2>/dev/null || true git push 2>/dev/null || true fi ``` ### Technical Analysis After a successful upgrade, the script changes into the configured workspace and executes `git add -A`. This stages every modified, deleted, and untracked file in the repository rather than limiting the operation to files produced by the upgrade. The script then commits the staged content and invokes `git push` using the user's existing Git configuration and credentials. It does not: - Display the staged diff. - Restrict the files included in the commit. - Validate the destination remote. - Request confirmation before transmitting content. - Report failures, because command output and errors are suppressed and each operation ends with `|| true`. This Git behavior is not disclosed in `SKILL.md` and is unnecessary for the core OpenClaw upgrade operation. ### Attack Path 1. The workspace contains sensitive, unrelated, or attacker-induced changes, including potentially untracked files. 2. The workspace is a Git repository with a configured remote, and the user has credentials capable of pushing to it. 3. The user invokes the upgrade script. 4. Once the upgrade succeeds, `git add -A` stages all changes throughout the workspace. 5. The script creates a commit without presenting its contents to the user. 6. `git push` sends the commit to the configured remote using the user's credentials. 7. Because all output is suppressed, the user may not realize that unrelated con ...[truncated 908 chars]- Remediation
View remediation
