T05 · Unauthorized Access and Privilege Escalation
- Location
index.py:20- Finding
Unrestricted Access to Persistent Agent Workspace State
- Content
View full analysis
Vulnerability Details
File Location:
index.py, lines 20-25, 33-36, 46-49, 57, 63-68, and 173-185
Vulnerability Type: Access beyond least-privilege requirements
Risk Level: MediumVulnerable Code
python BASE_DIR = r'C:\Users\Administrator\.openclaw\workspace' MEMORY_FILE = os.path.join(BASE_DIR, 'MEMORY.md') PROJECTS_FILE = os.path.join(BASE_DIR, 'PROJECTS.md') MEMORY_DIR = os.path.join(BASE_DIR, 'memory') KG_DIR = os.path.join(BASE_DIR, 'knowledge_graph') OPTIMIZATION_LOG = os.path.join(BASE_DIR, 'memory', 'optimization循环.md')python if os.path.exists(MEMORY_FILE): with open(MEMORY_FILE, 'r', encoding='utf-8') as f: content = f.read() lines = len(content.split('\n'))python if os.path.exists(PROJECTS_FILE): with open(PROJECTS_FILE, 'r', encoding='utf-8') as f: content = f.read()python daily_files = [f for f in os.listdir(MEMORY_DIR) if f.startswith('2026-') and f.endswith('.md')]python kg_file = os.path.join(KG_DIR, 'graph.json') if os.path.exists(kg_file): with open(kg_file, 'r', encoding='utf-8') as f: kg = json.load(f)python # Append to the log if os.path.exists(OPTIMIZATION_LOG): with open(OPTIMIZATION_LOG, 'r', encoding='utf-8') as f: existing = f.read() content = existing + content else: content = "# 记忆系统优化循环日志\n" + content with open(OPTIMIZATION_LOG, 'w', encoding='utf-8') as f: f.write(content)Technical Analysis
The script is bound to a hard-coded global OpenClaw workspace under the Windows Administrator profile. When invoked, it reads long-term memory, project information, daily-memory metadata, and knowledge-graph data without requiring the caller to select or authorize the workspace. It also writes a persistent file inside the Agent's memory directory.
A diagnostic skill should follow least privilege by operating ...[truncated 1888 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the hard-coded Administrator workspace path.
- Require the workspace to be supplied explicitly through a command-line argument or trusted configuration source.
- Resolve the path with
os.path.realpathand verify that it is inside an approved workspace root. - Reject paths belonging to unexpected users or privileged profiles.
- Default to a read-only diagnostic mode and require an explicit option such as
--write-logbefore changing persistent state. - Display the exact files that will be read or written and obtain confirmation before accessing sensitive Agent memory.
- Open the log in append mode rather than reading and rewriting the entire file.
- Apply restrictive file permissions to the generated log and avoid recording sensitive memory contents.
- Handle missing directories and malformed graph data safely so that validation failures do not cause unintended behavior.
- Run the skill under a dedicated, non-administrative account with access only to the intended workspace.
