T09 · Insecure Skill Coding Practices
- Location
scripts/create_pipeline.sh:8- Finding
Unvalidated Topic Slug Permits Path Traversal and Out-of-Scope File Creation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create_pipeline.sh, lines 8-28
Vulnerability Type: Path traversal through an unvalidated filesystem path component
Risk Level: HighVulnerable Code
bash TOPIC_SLUG="${1:?Usage: $0 <topic-slug> [topic-display-name]}" TOPIC_NAME="${2:-$TOPIC_SLUG}" # Resolve workspace-relative path WORKSPACE="${OPENCLAW_WORKSPACE:-$HOME/.openclaw/workspace}" BASE_DIR="${WORKSPACE}/memory/learning/${TOPIC_SLUG}" if [ -d "$BASE_DIR" ]; then echo "Error: Topic directory already exists: $BASE_DIR" echo "Remove it first or choose a different slug." exit 1 fi # Create directory structure mkdir -p "${BASE_DIR}/sessions" mkdir -p "${BASE_DIR}/knowledge" # Create initial state.json NOW=$(date -u '+%Y-%m-%dT%H:%M:%SZ') cat > "${BASE_DIR}/state.json" << EOFTechnical Analysis
TOPIC_SLUGis accepted directly from the first command-line argument and appended to the intended learning directory without validation or canonical-path containment verification. Shell quoting prevents word splitting and wildcard expansion, but it does not neutralize path traversal sequences such as../.The documentation instructs the agent to generate a slug, but the executable script does not enforce that requirement. A caller can therefore supply traversal components that cause
BASE_DIRto resolve outside${WORKSPACE}/memory/learning.The existing-directory check only prevents use of a final path that already exists. It does not prevent creation of a new attacker-selected directory outside the intended location.
Attack Path
- An attacker or untrusted caller invokes
create_pipeline.shwith a crafted topic slug containing enough../components to escapememory/learning. - The script constructs
BASE_DIRby concatenating the untrusted value to the workspace path. - The operating system resolves the traversal components when ...[truncated 1404 chars]
- An attacker or untrusted caller invokes
- Remediation
View remediation
Remediation Suggestions
-
Enforce a strict slug allowlist before constructing any path:
bash if [[ ! "$TOPIC_SLUG" =~ ^[a-z0-9]+(-[a-z0-9]+)*$ ]]; then echo "Error: topic slug must contain only lowercase letters, digits, and single hyphen separators." >&2 exit 1 fi -
Canonicalize both the learning root and candidate destination, then verify containment before writing.
-
Reject slashes, backslashes,
.components,..components, control characters, and empty values. -
Validate
OPENCLAW_WORKSPACEas an absolute, trusted directory or derive it from trusted configuration rather than arbitrary inherited environment data. -
Create files using restrictive permissions, such as
umask 077, if pipeline state may contain private learning or notification information. -
Add regression tests for
../, absolute-looking paths, repeated separators, control characters, and symbolic-link edge cases.
-
