T05 · Unauthorized Access and Privilege Escalation
- Location
src/index.js:630- Finding
Default Configuration Exposes an Unauthenticated Dashboard Beyond Loopback
- Content
View full analysis
{ const profile = process.env.OPENCLAW_PROFILE; ``` ### Technical Analysis The configuration declares `localhost` as the default host, but the configured host is not supplied to `server.listen`. Calling `server.listen(PORT)` causes Node.js to listen on an unspecified address, commonly all available IPv4 or IPv6 interfaces, rather than enforcing loopback-only access. At the same time, authentication defaults to `none`. The authentication middleware is skipped entirely in this mode. The server exposes sensitive OpenClaw information, including session metadata, memory statistics, token usage, system vitals, cron data, operators, and Server-Sent Events. This behavior is inconsistent with the documented `http://localhost:3333` deployment model and exceeds the minimum network privilege needed for a local monitoring dashboard. ### Attack Path 1. A user installs the Skill and starts it using the documented `node lib/server.js` command. 2. No authentication environment variables are configured, so the mode defaults to `none`. 3. The server calls `listen(PORT)` without the configured `localhost` host. 4. A host with network access to the machine connects to TCP port 3333. 5. The attacker requests endpoints such as: - `GET /api/state` - `GET /api/sessions` - `GET ...[truncated 794 chars]- Remediation
View remediation
{ // Startup logging }); ``` 2. Default to an explicit loopback address such as `127.0.0.1` rather than a hostname that may resolve unexpectedly. 3. Refuse startup when authentication is `none` and the configured host is not loopback. 4. Emit a prominent warning if the server is configured for non-loopback access. 5. Require an authenticated mode for Tailscale, Cloudflare, LAN, container, or public deployments. 6. Add automated tests that verify the default server is unreachable through non-loopback interfaces. 7. Ensure the bundled `lib/server.js` is rebuilt after correcting the source. ]]>
