T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:886- Finding
Race-Prone Automatic Device Pairing Can Approve an Unauthorized Client
- Content
View full analysis
` 3. Confirm: "You're approved and connected!" **Security rules:** - Only auto-approve during an active onboarding conversation - Only approve ONE device per onboarding flow - If multiple requests arrive, approve only the first and alert the user - Outside onboarding, surface pairing requests for manual approval ``` ### Technical Analysis The onboarding procedure authorizes a pending device based on a mutable display name and request arrival order. Neither the device's cryptographic fingerprint nor a user-visible pairing challenge is verified before approval. The instruction to approve the first request is particularly unsafe. An attacker who can reach the gateway during an onboarding session may submit a pairing request before the legitimate phone and use an expected name such as `OpenPot` or `openclaw-ios`. Display names are identifiers, not authentication factors. Although automatic approval is limited to an active onboarding flow, this only narrows the attack window; it does not establish that the selected request belongs to the user. ### Attack Path 1. The victim starts an OpenPot onboarding conversation. 2. The attacker reaches the exposed gateway through the LAN, VPN, Tailscale network, or another accessible route. 3. The attacker submits a device-pairing request using the name `OpenPot` or `openclaw-ios`. 4. The attacker's request appears before the legitimate device or is the only request visible at that instant. 5. Following the Skill instructions, the agent approves the first matching request. 6. The attacker obtains an approved device identity and can use the access granted t ...[truncated 543 chars]- Remediation
View remediation
