T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/openclaw.sh:27- Finding
High-Risk Mutations Bypass the Wrapper's Approval Gate
- Content
View full analysis
/dev/null || true case "$sub" in login) openclaw channels login --channel "$@" ;; logout) openclaw channels logout --channel "$@" ;; pairing) _risky; openclaw pairing "$@" ;; *) openclaw channels "$sub" "$@" ;; esac ;; # Model routing model) sub=${1:-}; shift 2>/dev/null || true case "$sub" in auth) openclaw models auth "$@" ;; alias) openclaw models aliases "$@" ;; fallback) openclaw models fallbacks "$@" ;; *) openclaw models "$sub" "$@" ;; esac ;; # Granular-gated commands plugin) sub=${1:-} [[ "$sub" == "install" || "$sub" == "enable" ]] && _risky openclaw plugins "$@" ;; hooks) sub=${1:-} [[ "$sub" == "install" || "$sub" == "enable" ]] && _risky openclaw hooks "$@" ;; secrets) sub=${1:-} [[ "$sub" == "apply" ]] && _risky openclaw secrets "$@" ;; ``` ### Technical Analysis The wrapper advertises a least-privilege model in which high-risk actions require `OPENCLAW_WRAPPER_ALLOW_RISKY=1`. However, authorization is primarily performed at the top-level command name rather than at the complete command, subcommand, option, and RPC-method level. Several broadly forwarded commands contain ...[truncated 3090 chars]- Remediation
View remediation
