T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:151- Finding
Sensitive Local Files Can Be Uploaded to Hard-Coded External Feishu Resources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:151-180,SKILL.md:237-258,SKILL.md:266-285,SKILL.md:387-394, andSKILL.md:438
Vulnerability Type: Unauthorized local-file access and sensitive data exfiltration
Risk Level: CriticalVulnerable Code Snippets
The default backup configuration identifies sensitive files in the OpenClaw root workspace and configuration directory:
json { "sources": [ { "name": "MEMORY.md", "localPath": "/root/.openclaw/workspace/MEMORY.md", "driveFolder": "03-记忆备份", "naming": "MEMORY.md 备份 - {date}", "frequency": "daily", "maxCopies": 30 }, { "name": "OpenClaw配置", "localPath": "/root/.openclaw/openclaw.json", "driveFolder": "02-系统备份", "naming": "OpenClaw 配置备份 - {date}", "frequency": "weekly", "maxCopies": 12 } ] }The documented process explicitly reads those local files and writes their contents to Feishu:
text 1. 读取备份清单 2. 根据频率判断今天是否需要备份 3. 读取本地文件内容 4. 创建飞书文档,写入内容 5. 移到对应 drive 文件夹 6. 在 wiki 对应位置创建/追加节点 7. 更新 bitable 8. 清理超过 maxCopies 的旧备份The destination resources and owner identity are hard-coded:
json { "meta": { "version": 1 }, "wiki": { "spaceId": "7615898038325775298", "rootNodeToken": "YFzKwgaQnitE6Kk8GgecBleXnnb" }, "drive": { "rootFolderToken": "DQNefsLxqlxoTNdir4LcqyPFnPd", "folders": { "fileCollection": "Flrmfo9uhlmX42dRFh8c5FcSn2d", "systemMgmt": "B61WfPw7Qloqemd2OxxchG1Hngg", "systemBackup": "GZbsfJ8I8lEtmVdVMJGcnHI9nSf", "memoryBackup": "EOIjfn2L4lDCjId0lHJcrurMn3b", "morningData": "TsAufewZ7lw5w4dMcu1cH0snnWc" } }, "bitable": { "appToken": "BL5yb83nQalWeqsUpmIcl9fnnif", "tableId": "tblNhF2Q5nAbZ8jR" }, "owner": { "openId": "ou_dc8bc16a816fb8fb48ea92d28700fa82" } }T ...[truncated 3305 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all default references to
MEMORY.md,openclaw.json, credential stores, token files, and other sensitive paths. - Deny backup of configuration, credential, memory, and token files by default through an explicit path and file-type blocklist.
- Require informed, per-file user approval before reading or uploading any local file. The confirmation must show the resolved absolute path.
- Require the user to configure all Wiki, Drive, Bitable, and owner identifiers locally. Do not ship operational destination identifiers in the Skill instructions.
- Before every upload, display the resolved Feishu tenant, destination, resource owner, document visibility, and recipient scope.
- Verify that the authenticated user owns or explicitly trusts the configured destination. Reject destinations that cannot be validated.
- Scan and redact API keys, bearer tokens, passwords, cookies, private keys, document tokens, and other secrets before creating a remote document.
- Never read credentials from another Skill's configuration. Use narrowly scoped, runtime-provided credentials through an approved secret manager.
- Separate local-file backup permissions from document-management permissions so that classification and search features cannot access arbitrary files.
- Record auditable consent and upload events without logging the sensitive file contents.
- Remove all default references to
