T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:39- Finding
Unrestricted Retrieval of Active, Reset, and Deleted Conversation Transcripts
- Content
View full analysis
/sessions/` (default: `~/.openclaw/agents//sessions/`). Use the `agent=` value from the system prompt Runtime line. - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session - **`.jsonl.reset.Z`** - Transcript archived by `/new` or `/reset` - **`.jsonl.deleted.Z`** - Transcript archived when a session was deleted When searching history, include the archived (`.reset.*`, `.deleted.*`) variants too — they still contain real conversation content. The plain-glob examples below only catch the active `*.jsonl` files; use the "Include archived transcripts" snippet when you need full recall. ``` Additional affected instructions include user-message extraction at lines 116–123 and searches across all active and archived sessions at lines 174–185. ### Technical Analysis The skill directs the agent to access the complete session storage directory and explicitly encourages searching transcripts archived after a reset or deletion. These files can contain sensitive personal information, authentication material pasted into conversations, proprietary data, and contextual information unrelated to the current request. This design does not exploit an operating-system permission vulnerability; it relies on whatever filesystem access the agent already possesses. However, it breaks least-privilege boundaries at the application level by defaulting to broad historical access rather than limiting retrieval to a specifically identified session, date range, or conversation. Deleted and reset records are especially sensitive because users m ...[truncated 1909 chars]- Remediation
View remediation
