T05 · Unauthorized Access and Privilege Escalation
- Location
references/protocol-spec.md:47- Finding
Unrestricted Environment-Variable Expansion in Pipeline Parameters
- Content
View full analysis
Vulnerability Details
File Location:
references/protocol-spec.md, lines 47-51
Vulnerability Type: Arbitrary environment-variable access
Risk Level: HighVulnerable Code
markdown ## Variable Reference Syntax Steps can reference outputs from previous steps: - `$step_id.output.field` — Access a specific field from a step's output - `$step_id.output` — Access the entire output object - `$step_id.wave_score` — Access the WAVE score from a step - `$ENV_VAR` — Access environment variables (prefixed with no dot)Technical Analysis
The protocol permits pipeline parameters to reference arbitrary process environment variables. No variable allowlist, secret-name filtering, authorization check, or user-confirmation boundary is specified.
Environment variables commonly contain API keys, access tokens, signing secrets, cloud credentials, database connection strings, and private paths. Generic environment access exceeds the minimum privileges needed for ordinary Obsidian note orchestration.
Because resolved parameters can be consumed by actions such as
create_note,ai_expand,wave_check, and template execution, a secret may be written into the vault, submitted to an AI provider, included in pipeline output, or forwarded through progress telemetry.Attack Path
- An attacker or compromised local bridge client submits an
EXECUTE_PIPELINErequest. - An action parameter references a sensitive variable, such as an API-key environment variable.
- The pipeline resolver substitutes the environment variable's value.
- The substituted value is passed to a note, AI, template, or telemetry-producing action.
- The attacker recovers the secret from vault content, action output, logs, or pipeline notifications.
Impact Assessment
Successful exploitation can disclose any environment variable visible to the bridge process. The resulting scope depends on the process environment and may ...[truncated 183 chars]
- An attacker or compromised local bridge client submits an
- Remediation
View remediation
Remediation Suggestions
- Remove generic
$ENV_VARexpansion from remotely supplied pipelines. - If environment substitution is essential, use an explicit allowlist of non-sensitive variables configured by the vault owner.
- Reject variable names associated with secrets, tokens, credentials, keys, passwords, cookies, and connection strings.
- Require explicit user approval before resolving each allowed variable.
- Resolve variables only after authentication and action-level authorization.
- Mark resolved secrets as sensitive and prevent them from entering notes, logs, telemetry, error messages, or AI-provider requests.
- Run the bridge with a minimal sanitized environment and retrieve necessary secrets from a scoped secret manager.
- Add tests proving that unknown and sensitive variable references are rejected.
- Remove generic
