T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/copy_session_content.sh:4- Finding
Path Traversal Enables Session Disclosure and Unintended File Writes
- Content
View full analysis
[copy|summary]" exit 1 fi OLD_DIR="$HOME/.openclaw/agents/$OLD_ID/sessions" NEW_DIR="$HOME/.openclaw/agents/$NEW_ID/sessions" mkdir -p "$NEW_DIR" if [[ ! -d "$OLD_DIR" ]]; then echo "Old session dir not found: $OLD_DIR" exit 2 fi mapfile -t FILES < <(find "$OLD_DIR" -maxdepth 1 -type f \( -name '*.jsonl' -o -name 'sessions.json' \) | sort) if [[ ${#FILES[@]} -eq 0 ]]; then echo "No session files found in $OLD_DIR" exit 3 fi case "$MODE" in copy) for f in "${FILES[@]}"; do base=$(basename "$f") cp "$f" "$NEW_DIR/migrated-from-$OLD_ID-$base" echo "COPIED $f -> $NEW_DIR/migrated-from-$OLD_ID-$base" done ;; summary) OUT="$NEW_DIR/migration-summary-from-$OLD_ID.txt" { echo "Migration summary from $OLD_ID to $NEW_ID" echo "Generated: $(date -Is)" echo printf 'Files:\n' printf '%s\n' "${FILES[@]}" } > "$OUT" echo "WROTE $OUT" ;; ``` ### Technical Analysis The script accepts `OLD_ID` and `NEW_ID` as positional arguments and interpolates them directly into filesystem paths. It does not enforce an agent-ID character allowlist, canonicalize the resulting paths, or verify that they remain beneath `$HOME/.openclaw/agents`. Traversal sequences such as `../` can therefore cause the source or destination to resolve outside the intended agent directory. The destination is created with `mkdir -p`, after which `cp` or shell redirection writes files into the resolved location. Existing destination files may be overwritten. A pre-existing symbolic link within the destination path could also redi ...[truncated 1639 chars]- Remediation
View remediation
&2 exit 1 } } validate_id "$OLD_ID" validate_id "$NEW_ID" ``` 2. Define and canonicalize a trusted base directory: ```bash AGENT_ROOT="$(realpath -- "$HOME/.openclaw/agents")" OLD_DIR="$(realpath -- "$AGENT_ROOT/$OLD_ID/sessions")" ``` 3. For a destination that may not exist, canonicalize its existing parent and construct the final path only after validating the ID. 4. Verify that resolved paths remain direct descendants of the trusted root: ```bash [[ "$OLD_DIR" == "$AGENT_ROOT/"* ]] || exit 1 [[ "$NEW_DIR" == "$AGENT_ROOT/"* ]] || exit 1 ``` 5. Reject symbolic links in the destination path and verify ownership and permissions before writing. 6. Avoid silent overwrites by using `cp --no-clobber`, generating collision-resistant filenames, or requiring explicit overwrite confirmation. 7. Set restrictive permissions, such as `umask 077`, before creating directories or files containing session data. ]]>
