T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/file_manager.py:394- Finding
Caller-Supplied Delete Plan Bypasses Workspace Path Validation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/file_manager.py, lines 281-286 and 394-402
Vulnerability Type: Execution-time path validation bypass
Risk Level: HighVulnerable Code:
python def execute_delete(operations: List[FileOperation]) -> Tuple[bool, List[str]]: """Execute delete operations (move to trash).""" results = [] for op in operations: success, msg = move_to_trash(Path(op.source)) results.append(f"{'✓' if success else '✗'} {op.source}: {msg}") return True, resultspython elif cmd == "delete-confirm": if len(sys.argv) < 3: print(json.dumps({"error": "Operations JSON required"}, indent=2)) sys.exit(1) try: ops_data = json.loads(sys.argv[2]) operations = [FileOperation(**op) for op in ops_data] success, results = execute_delete(operations)Technical Analysis
The initial deletion-planning function calls
validate_path(), but the execution endpoint does not require operations to originate from that planner. Instead,delete-confirmdeserializes arbitrary caller-supplied JSON directly intoFileOperationobjects.execute_delete()then passes each untrustedsourcevalue directly tomove_to_trash()without repeating workspace containment checks, forbidden-pattern checks, existence checks, or operation-type validation. Consequently, the security boundary implemented byvalidate_path()can be bypassed by calling the execution command directly.The
confirm_requiredfield is also caller-controlled and is not enforced. No integrity mechanism binds an execution request to a previously generated plan.Attack Path
- Identify a filesystem file or directory accessible to the process but located outside
OPENCLAW_WORKSPACE. - Construct a JSON operation array containing that absolute path, for example:
json [{ "op": "delete", "source":
...[truncated 949 chars]
- Identify a filesystem file or directory accessible to the process but located outside
- Remediation
View remediation
Remediation Suggestions
- Call
validate_path()on every operation source immediately before execution. - Require the resolved source to remain beneath an explicitly configured allowed root.
- Reject unsupported operation names and ignore caller-supplied
confirm_requiredandsizevalues. - Bind execution requests to server-generated plans using a random plan identifier or an authenticated signature.
- Store plans internally rather than accepting complete operation objects from the command line.
- Recalculate target metadata and total size during execution.
- Defend against time-of-check/time-of-use and symlink races by using descriptor-relative filesystem APIs where available.
- Return an overall failure status if any individual operation fails.
- Call
