T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/ingest_all_content.py:115- Finding
Sensitive-path exclusions are not enforced during memory-index ingestion
- Content
View full analysis
List[Dict]: db_path = openclaw_home / "memory" / "main.sqlite" if not db_path.exists(): return [] rows = load_sqlite_rows( db_path, """ select path, start_line, end_line, text, updated_at from chunks order by path, start_line """, ) records: List[Dict] = [] for row in rows: location = f"{row['path']}:{row['start_line']}-{row['end_line']}" records.append( { "record_id": stable_id([str(db_path), location]), "source_type": "openclaw-memory-index", "source_path": str(db_path), "location": location, "timestamp": row["updated_at"], "speaker": "user", "conversation_id": row["path"], "content": row["text"], } ) return records ``` The project declares the following exclusions in `scripts/mbti_common.py:14-23`: ```python DEFAULT_EXCLUDED_PATTERNS = [ ".env", "credentials/*", "identity/*", "devices/*", "exec-approvals.json", "openclaw.json", "logs/*", "gateway*.log", ] ``` ### Technical Analysis The memory-index ingestor selects every row from the `chunks` table and copies each row's complete `text` value into the raw record collection. It does not apply `DEFAULT_EXCLUDED_PATTERNS`, an equivalent allowlist, or any secret-redaction logic. The exclusion list is exposed in the discovery manifest but is not enforced by this ingestion path. Consequently, authorization of the broad `openclaw-memory-index` source category can implicitly authorize indexed content from `.env`, credential, identity, approval ...[truncated 1828 chars]- Remediation
View remediation
