T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/scan_secrets.py:35- Finding
Unrestricted Filesystem Scanning Outside the Intended Workspace
- Content
View full analysis
Vulnerability Details
File Location:
scripts/scan_secrets.py, lines 35-49 and 64-65
Vulnerability Type: Unrestricted filesystem traversal
Risk Level: MediumVulnerable Code
python def main(root_dir): all_findings = [] for root, dirs, files in os.walk(root_dir): # Filter directories dirs[:] = [d for d in dirs if d not in EXCLUDE_DIRS] for file in files: if file in EXCLUDE_FILES or file.endswith((".png", ".jpg", ".jpeg", ".gif", ".pdf", ".zip", ".skill")): continue file_path = os.path.join(root, file) findings = scan_file(file_path) all_findings.extend(findings)python if __name__ == "__main__": target = sys.argv[1] if len(sys.argv) > 1 else "." main(target)Technical Analysis
The script accepts an arbitrary filesystem path from its first command-line argument and recursively opens files beneath that path. It does not canonicalize the target, verify that it is within the authorized OpenClaw workspace, or require explicit approval before scanning a location outside that workspace.
The implementation also does not validate each resolved file path before opening it. Consequently, a caller can select broad locations such as the filesystem root, a home directory, or a credential directory. File symlinks encountered during traversal may also reference files outside the nominal scan root.
Although detected values are masked and the reviewed code contains no network exfiltration mechanism, the output still reveals sensitive metadata, including filenames, line numbers, credential types, and fragments of matched values.
Attack Path
- An attacker, malicious automation, or injected instruction causes the Skill to invoke the script with an overly broad or sensitive path.
- The command-line argument is assigned directly to
targetwithout ...[truncated 1102 chars]
- Remediation
View remediation
Remediation Suggestions
- Resolve both the authorized workspace and requested target with
os.path.realpath(). - Reject any target that is not equal to or contained within the authorized workspace, using
os.path.commonpath()rather than unsafe string-prefix comparisons. - Require explicit user authorization before scanning any location outside the default workspace.
- Reject symbolic-link files, or resolve every candidate file and verify that its canonical path remains inside the approved boundary before opening it.
- Consider accepting only workspace-relative paths rather than unrestricted absolute paths.
- Document the precise scan boundary and report the canonical target before scanning.
- Run the scanner with a minimally privileged operating-system account.
Example boundary validation:
python workspace = os.path.realpath(os.environ["OPENCLAW_WORKSPACE"]) target = os.path.realpath(requested_target) if os.path.commonpath([workspace, target]) != workspace: raise ValueError("Scan target is outside the authorized workspace")- Resolve both the authorized workspace and requested target with
