T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fix.py:27- Finding
Direct Authorization Bypass and Broad Device Privilege Escalation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fix.py:27-34, 44-50, 101-162, 177-191;SKILL.md:66-71, 117-118
Vulnerability Type: Direct modification of trusted authentication state, unsafe privilege assignment, and approval bypass
Risk Level: HighVulnerable Code
scripts/fix.py:27-34defines a broad fallback permission set that includes administrative, approval, pairing, write, and secret-access capabilities:python FALLBACK_SCOPES = [ "operator.admin", "operator.read", "operator.write", "operator.approvals", "operator.pairing", "operator.talk.secrets", ]scripts/fix.py:44-50trusts the scopes contained in the first repair request without validating them against a restrictive allowlist:python def find_device_id_from_pending(): """从 pending repair 请求获取设备 ID""" if not os.path.exists(PENDING): return None, None with open(PENDING) as f: pending = json.load(f) for req in pending.values(): if req.get("isRepair"): return req.get("deviceId"), req.get("scopes", FALLBACK_SCOPES) return None, Nonescripts/fix.py:101-162generates a new privileged token, directly rewrites trusted pairing and authentication files, and deletes matching pending requests:python def fix(device_id, full_scopes, dry_run=False, force=False): """执行修复""" new_token = f"cli_admin_{secrets.token_urlsafe(20)}" ts = int(datetime.now().timestamp() * 1000) # Read current state with open(PAIRED) as f: paired = json.load(f) with open(AUTH) as f: auth = json.load(f) if device_id not in paired: red(f"设备 {device_id} 不在 paired.json 中!") red(f"可用设备: {list(paired.keys())}") sys.exit(1) old_scopes = paired[device_id].get("scopes", []) # Show changes first (检查点!) show_changes(device_id, old_scopes, full_scopes, n ...[truncated 5579 chars]- Remediation
View remediation
Remediation Suggestions
- Remove direct trust-database modification. Do not grant scopes by editing
paired.jsonordevice-auth.json. Use OpenClaw's official authenticated pairing and approval APIs. - Require independent administrative approval. Scope elevation must be authorized by an already trusted administrator rather than by the device requesting elevation.
- Remove or strictly restrict
--force. Noninteractive privilege elevation should not be available to ordinary callers. If automation is essential, require a separately protected administrative credential and explicit policy authorization. - Apply a minimal scope allowlist. Never trust scope arrays read from
pending.json. Parse and validate every requested scope, reject unknown or excessive values, and grant only the minimum permissions required for the specific repair. - Avoid the broad fallback scope set. Failure to locate a valid, authenticated request should terminate safely rather than automatically granting administrative, pairing, approval, write, and secret-access scopes.
- Verify device identity and request provenance. Bind each repair request cryptographically to the requesting device and verify that the request is current, authentic, and intended for the exact device being modified.
- Preserve audit evidence. Record the request, approver identity, old and new scopes, timestamp, and outcome in an append-only audit log. Do not silently delete pending records as part of elevation.
- Use transactional and atomic updates. If local state must be updated, write validated data to securely created temporary files, preserve restrictive file permissions and ownership, flush data, atomically replace the originals, and roll back all changes if any step fails.
- Do not replace complete token maps unnecessarily. Avoid deleting unrelated token metadata or roles when updating one operator credential.
- Add negative security tests. Tes ...[truncated 196 chars]
- Remove direct trust-database modification. Do not grant scopes by editing
