T05 · Unauthorized Access and Privilege Escalation
- Location
lib/image_generator.py:203- Finding
Undocumented API Credential Discovery from Workspace Files
- Content
View full analysis
Optional[str]: env_key = os.getenv('DASHSCOPE_API_KEY') if env_key: return env_key config_paths = [ os.path.expanduser('~/.openclaw/workspace/TOOLS.md'), ] for path in config_paths: if os.path.exists(path): try: with open(path, 'r', encoding='utf-8') as f: content = f.read() import re patterns = [ r'API Key[`:\s]+`?([a-zA-Z0-9-]+)`?', ] for pattern in patterns: match = re.search( pattern, content, re.IGNORECASE | re.DOTALL ) if match: return match.group(1) except Exception: pass return None ``` The discovered credential is subsequently used as a bearer token: ```python headers = { 'Content-Type': 'application/json', 'Authorization': f'Bearer {self.api_key}' } response = requests.post( WANX_API_URL, headers=headers, json=payload, timeout=120 ) ``` ### Technical Analysis The documented credential mechanism is the `DASHSCOPE_API_KEY` environment variable. However, the implementation also searches a general-purpose workspace document, `~/.openclaw/workspace/TOOLS.md`, without explicit user authorization. The generic regular expression can match an API key unrelated to DashScope. This violates least privilege because the image-generation component gains ac ...[truncated 1322 chars]- Remediation
View remediation
