T05 · Unauthorized Access and Privilege Escalation
- Location
index.js:24- Finding
Unrestricted Disclosure of Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
index.js, lines 24-40
Vulnerability Type: Missing authorization for access to persistent session data
Risk Level: Mediumjs async hydrate(ctx) { try { const state = fs.existsSync(statePath) ? JSON.parse(fs.readFileSync(statePath, 'utf8')) : {}; const last = fs.existsSync(lastPath) ? fs.readFileSync(lastPath, 'utf8') : ""; return { ok: true, hydration: { lastSession: last, state } };Technical Analysis
The exported
hydrate(ctx)method reads and returns the complete contents of the persistentstate.jsonandlast-session.mdfiles. Although the method accepts a context object, it does not inspectctx, authenticate the caller, verify authorization scopes, request consent, or restrict the returned fields.These files are intended to contain runtime state, prior-session text, notes, decisions, open loops, and session references. Consequently, any component that can invoke this native skill method receives all stored information rather than a minimal, purpose-specific subset.
The file paths are fixed beneath the current user's home directory, so this issue does not provide arbitrary-file-read capability by itself. It also does not elevate operating-system privileges. The vulnerability is an access-control failure within the agent environment: callers with permission to invoke the skill may cross the intended confidentiality boundary around persistent agent memory.
Attack Path
- An untrusted, compromised, or insufficiently privileged agent component obtains the ability to invoke the native skill.
- The component calls the exported
hydrate()method without needing to provide credentials or an authorized scope inctx. - The method reads
~/.openclaw/workspace/benos/runtime/state.jsonand~/.openclaw/workspace/benos/runtime/last-session.mdusing the ...[truncated 971 chars]
- Remediation
View remediation
Remediation Suggestions
- Enforce caller authentication and authorization through
ctxbefore reading either file. Reject calls lacking a trusted identity and an explicit memory-read scope. - Define granular permissions, such as separate scopes for current state, historical session text, notes, and decisions.
- Return only fields required for the caller's declared operation instead of returning the complete files.
- Redact secrets, credentials, tokens, personal data, and other sensitive values before constructing the response.
- Consider denying access to
last-session.mdby default and requiring explicit user consent for historical-session retrieval. - Validate the size and schema of stored data before parsing or returning it, and impose response-size limits.
- Add privacy-preserving audit logs recording the caller identity, requested scope, timestamp, and result without recording sensitive memory contents.
- Add tests confirming that anonymous callers, unauthorized roles, and callers with insufficient scopes cannot retrieve persistent memory.
- Enforce caller authentication and authorization through
