T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/ping-me-cancel.sh:16- Finding
Cancellation Script Can Delete Unrelated OpenClaw Cron Jobs
- Content
View full analysis
/dev/null | python3 -c ' import json, sys partial = sys.argv[1] try: data = json.load(sys.stdin) jobs = data.get("jobs", data) if isinstance(data, dict) else data if isinstance(jobs, list): for j in jobs: if isinstance(j, dict) and j.get("id", "").startswith(partial): print(j["id"]) sys.exit(0) except Exception: pass print("") ' "$JOB_ID" 2>/dev/null) || FULL_ID="" if [ -n "$FULL_ID" ]; then JOB_ID="$FULL_ID" fi fi RESULT=$("$OPENCLAW" cron rm "$JOB_ID" 2>&1) ``` ### Technical Analysis The cancellation script resolves a partial identifier against every cron job returned by `openclaw cron list --json`. It does not verify that the matched job belongs to this Skill or that its `name` is `ping-me`. The script also accepts a full identifier and passes it directly to `openclaw cron rm` without retrieving and validating the corresponding job first. Consequently, the cancellation operation is not restricted to reminders created by this project. Partial identifiers introduce an additional ambiguity problem: the script selects the first matching job without checking whether multiple jobs share that prefix. Although the listing script filters displayed jobs by name, that protection is not applied in the cancellation script. ### Attack Path 1. An attacker or user obtains, guesses, or is given the full ID or a unique prefix of an unrelated OpenClaw cron job. 2. The identifier is supplied to `ping-me-cancel.sh`. 3. For a partial identifier, the script searches all visible cron jobs and resolves the first matching ID without checking its job name ...[truncated 799 chars]- Remediation
View remediation
