T05 · Unauthorized Access and Privilege Escalation
- Location
jewellery_openclaw_skill.py:190- Finding
Unauthenticated Endpoint Permits Abuse of Privileged Cloud Services
- Content
View full analysis
Vulnerability Details
File Location:
jewellery_openclaw_skill.py, lines 190-205
Vulnerability Type: Missing authentication, authorization, and abuse controls
Risk Level: HighVulnerable Code
python @app.post("/api/v1/jewellery/process") async def process_jewellery_content(payload: WebhookPayload): # This acts as the synchronous webhook return, processing in background if needed # Wait for completion to return real results for integration ease. import os parent_folder = os.getenv("DRIVE_FOLDER_ID", "root") result = await run_pipeline(payload, parent_folder) if result["status"] == "error": raise HTTPException(status_code=500, detail=result["message"]) return result if __name__ == "__main__": import uvicorn uvicorn.run(app, host="0.0.0.0", port=8000)Technical Analysis
The processing endpoint is exposed on all network interfaces and does not require an API key, authenticated service identity, signed webhook, or user session. It also lacks authorization checks, request quotas, and rate limiting.
Every accepted request can invoke operations using the application's configured Anthropic, Vertex AI, Redis, and Google Drive credentials. The endpoint therefore allows an unauthenticated caller to indirectly exercise the application's cloud privileges, even though the caller does not possess the underlying credentials.
A cache hit only occurs for an identical downloaded image hash. An attacker can bypass caching by supplying unique image resources or changing the image bytes for every request.
Attack Path
- An attacker discovers or reaches TCP port 8000 on the host.
- The attacker sends a POST request to
/api/v1/jewellery/processwith an arbitraryimage_url,product_name, andmetadata. - The application downloads the image and invokes Anthropic prompt generation.
- It starts two billable Vertex Imagen ...[truncated 915 chars]
- Remediation
View remediation
Remediation Suggestions
- Require authentication using a service-to-service identity mechanism, OAuth access token, or high-entropy API key.
- For webhooks, require an HMAC signature that covers the timestamp and raw request body. Reject expired timestamps and replayed request identifiers.
- Authorize each authenticated principal for the requested operation and configured Drive destination.
- Place the service behind an authenticated API gateway or private network rather than exposing Uvicorn directly.
- Add per-principal and global rate limits, concurrency limits, daily generation quotas, and billing alerts.
- Enforce request deduplication and reject excessive queued work.
- Use a dedicated Google service account with access only to the intended Drive folder.
- Return generic client-facing errors and record detailed provider errors only in access-controlled logs.
