T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:59- Finding
Persistent OpenClaw Gateway Service Runs with Unnecessary Root Privileges
- Content
View full analysis
/etc/systemd/system/openclaw-gateway.service << 'EOF' [Unit] Description=OpenClaw Gateway After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/bin/env openclaw gateway Restart=always RestartSec=5 User=root WorkingDirectory=/root/.openclaw Environment=HOME=/root [Install] WantedBy=multi-user.target EOF systemctl daemon-reload && systemctl enable openclaw-gateway ``` ### Technical Analysis The optional systemd unit executes the OpenClaw gateway as `root`, automatically restarts it after failure, and enables it to start after reboot. Although persistence is explicitly disclosed and is functionally relevant when the gateway must survive reboots, granting the gateway unrestricted root privileges exceeds the minimum permissions normally required by a network-facing service. Any vulnerability in the gateway, its extensions, configuration parsing, or command-handling logic would consequently execute in a root context. The use of: ```ini ExecStart=/usr/bin/env openclaw gateway ``` also fails to pin the service to a specific, reviewed executable path. The effective executable depends on the systemd service environment's `PATH`, making executable provenance less explicit than an absolute path. No systemd sandboxing controls are configured. In particular, the service lacks controls such as `NoNewPrivileges`, filesystem protections, private temporary storage, restricted capabilities, and system-call filtering. Its working directory and home directory are both under `/root`, potentially exposing root-owned OpenClaw configuration and credentials to a compromised gateway process. ### Attack Path 1. An administrator follows the Skill and installs the systemd unit. 2. The administrator enables the service, causing it to ...[truncated 1166 chars]- Remediation
View remediation
