T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:9- Finding
Unrestricted Cross-Session Conversation History Access
- Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` ```markdown ### Search across ALL sessions for a phrase ```bash rg -l "phrase" ~/.openclaw/agents//sessions/*.jsonl ``` ``` ### Technical Analysis The skill instructs the agent to access complete historical conversation transcripts and provides a wildcard command for searching every session belonging to an agent. Session JSONL files may contain user and assistant messages, tool calls, tool results, identifiers, operational details, and other sensitive information. The instructions do not establish authorization boundaries such as requiring an explicitly identified session, confirming that the requester is entitled to access the selected history, limiting searches to the minimum necessary scope, or redacting unrelated sensitive data before returning results. A request for historical context can therefore cause the agent to inspect sessions unrelated to the current request. This violates least-privilege and data-minimization principles. The issue concerns access to data already readable by the ...[truncated 1425 chars]- Remediation
View remediation
" SESSION_FILE="$HOME/.openclaw/agents//sessions/${SESSION_ID}.jsonl" jq -r ' select(.type == "message") | select(.message.role == "user" or .message.role == "assistant") | .message.content[]? | select(.type == "text") | .text ' "$SESSION_FILE" | rg -i --fixed-strings -- "" ``` 10. Validate `SESSION_ID` against a strict identifier format and verify the resolved path remains inside the authorized session directory before reading it. ]]>
