T09 · Insecure Skill Coding Practices
- Location
scripts/restore.sh:90- Finding
Restore Archive Is Not Confined to the Intended OpenClaw Directory
- Content
View full analysis
/dev/null | grep -qE '^\.\./|/\.\./'; then echo "Error: archive contains path traversal sequences (../) — aborting." exit 1 fi } ``` The archive is subsequently extracted into the parent of the configured OpenClaw home: ```bash PARENT_DIR="$(dirname "$OPENCLAW_HOME")" mkdir -p "$PARENT_DIR" echo "Extracting..." tar -xzf "$WORK_ARCHIVE" -C "$PARENT_DIR" ``` ### Technical Analysis The validation only searches archive member names for `../` at the beginning or after a forward slash. It does not enforce the more important security invariant that every archive member must belong to the exact expected root directory, such as `.openclaw/`. For the default target, extraction occurs in `$HOME`, not in a newly created and isolated `.openclaw` directory. Therefore, a crafted archive can contain unrelated top-level entries such as `.ssh/config`, `.bashrc`, or `other-directory/file`. These entries do not contain `../`, pass the traversal check, and are extracted under the target parent rather than under `.openclaw`. The validator also does not explicitly reject: - Absolute archive paths - A member named exactly `..` - Platform-specific separator variants - Symbolic or hard-link entries whose targets escape the intended root - Archives whose root directory does not match `basename "$OPENCLAW_HOME"` The behavior of some absolute paths and link entries can vary between `tar` implementations, but the unrelated-top-level-entry issue is sufficient to bypass the intended extraction boundary. ### Attack Path 1. An attacker creates or modifies a gzip-compressed tar ...[truncated 1404 chars]- Remediation
View remediation
