T09 · Insecure Skill Coding Practices
- Location
server/index.js:376- Finding
Unauthenticated Command Injection in the Global Package Update Endpoint
- Content
View full analysis
{ try { const { version } = req.body const packageSpec = version ? `openclaw@${version}` : 'openclaw@latest' console.log(`[Server] Updating OpenClaw via npm: ${packageSpec}`) // Execute npm update command const { execSync } = await import('child_process') const output = execSync(`npm install -g ${packageSpec}`, { encoding: 'utf8', timeout: 120000 }) ``` ### Technical Analysis The `/api/npm/update` route does not use `authMiddleware`. Therefore, any client that can reach the backend can invoke this privileged operation regardless of whether dashboard authentication is enabled. The request-controlled `version` value is embedded directly into a command string passed to `execSync`. Because `execSync` invokes a shell when given a string, shell metacharacters in `version` can alter the intended command and execute additional operating-system commands. The endpoint also performs a global npm installation, which may modify system-wide executable files and packages. Its effective privileges are those of the backend process and may be especially severe if the service runs as an administrator or root user. ### Attack Path 1. An attacker discovers or gains network access to the backend service. 2. The attacker sends a POST request to `/api/npm/update`. 3. The request body supplies a maliciously constructed `version` containing shell syntax. 4. The server concatenates that value into `npm install -g openclaw@...`. 5. `execSync` passes the resulting string to the system shell. 6. The injected command executes with the backend process's privileges. ### Impact Assessment Successful exploitation provides arbitrary command execution under the server account. An attacker ma ...[truncated 398 chars]- Remediation
View remediation
