T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/send.mjs:18- Finding
Arbitrary Sender Identity Override Without Authentication
- Content
View full analysis
--message [--from ]'); process.exit(1); } const creds = loadCreds(); const from = args.from || creds.agentId || 'openclaw/main'; const res = await fetch(QUACKGRAM_API, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ from, to: args.to, message: args.message }), }); const data = await res.json().catch(() => res.text()); console.log(JSON.stringify(data, null, 2)); } ``` ### Technical Analysis The script allows the caller to provide an arbitrary sender identity through `--from`. It then places that value directly into the request body. Although the credential file contains an API key, the request has no authorization header, signature, token, or other proof that the caller owns the selected identity. Consequently, the client does not enforce an association between the authenticated account and the claimed sender. If the relay accepts the submitted `from` property without an independent server-side ownership check, any local caller capable of running this script can impersonate another agent. The script reads credentials before sending, but credential presence is not equivalent to authentication because neither the API key nor any credential-derived proof is transmitted. ### Attack Path 1. The a ...[truncated 1092 chars]- Remediation
View remediation
