T09 · Insecure Skill Coding Practices
- Location
scripts/guardian.sh:10- Finding
Arbitrary Command Execution Through Unvalidated OPENCLAW_CMD
- Content
View full analysis
> "$LOG_FILE" 2>&1 sleep 10 if is_gateway_running; then log "doctor --fix 修复成功,Gateway 已恢复" return 0 fi return 1 } ``` ```bash nohup $OPENCLAW_CMD gateway >> "$LOG_FILE" 2>&1 & ``` ### Technical Analysis `OPENCLAW_CMD` is obtained from an environment variable and expanded as an unquoted shell command. Bash performs word splitting on its contents, allowing the value to specify an executable and attacker-selected arguments rather than only the intended OpenClaw executable. For example, an environment value such as `OPENCLAW_CMD='sh -c id'` causes the repair operation to evaluate an invocation equivalent to: ```bash sh -c id doctor --fix ``` The shell consequently runs `id` instead of the expected OpenClaw repair operation. More consequential shell commands could be supplied in the same way. The issue is reachable both during `doctor --fix` repair and during the post-rollback gateway restart. This is not an independent privilege-escalation primitive: exploitation requires the ability to influence the watchdog's startup environment. However, the injected command inherits all privileges, filesystem access, credentials, and network access of the watchdog process. ### Attack Path 1. An attacker gains the ability to set or alter the environment used to launch `guardian.sh`, such as through an insecure service definition, wrapper script, container environment, or shell startup configuration. 2. The attacker sets `OPENCLAW_CMD` to an executable and malicious argument sequence, for example `sh -c `. 3. The attacker waits for or causes `is_gateway_running` to report that t ...[truncated 883 chars]- Remediation
View remediation
&2 exit 1 } if [ ! -f "$OPENCLAW_BIN" ] || [ ! -x "$OPENCLAW_BIN" ]; then echo "Invalid OpenClaw executable" >&2 exit 1 fi "$OPENCLAW_BIN" doctor --fix >> "$LOG_FILE" 2>&1 nohup "$OPENCLAW_BIN" gateway >> "$LOG_FILE" 2>&1 & ``` ]]>
