T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fetch_repo.py:33- Finding
Undisclosed Access to a User Credential File
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_repo.py, lines 33–48 and 61–64
Vulnerability Type: Undisclosed credential-file access
Risk Level: MediumVulnerable Code
python def load_token() -> str: """Prefer the environment variable; otherwise read ~/.openclaw/.env.""" token = os.environ.get("GITHUB_TOKEN", "") if token: return token env_file = os.path.expanduser("~/.openclaw/.env") try: with open(env_file, "r", encoding="utf-8") as f: for line in f: line = line.strip() if line.startswith("GITHUB_TOKEN="): value = line.split("=", 1)[1].strip().strip('"').strip("'") if value: return value except OSError: pass return ""The retrieved token is subsequently attached to network requests:
python if token: request_headers["Authorization"] = f"Bearer {token}" if headers: request_headers.update(headers) try: with urllib.request.urlopen( urllib.request.Request(url, headers=request_headers), timeout=30 ) as response:Technical Analysis
When
GITHUB_TOKENis unavailable in the process environment,load_token()silently falls back to reading~/.openclaw/.env. It parses that file for aGITHUB_TOKENentry and returns the credential without requiring explicit opt-in or notifying the user that a credential file was accessed.This behavior conflicts with the documented authorization model:
SKILL.md, lines 17–20, states that the Skill reads only the system environment variable and does not read or create.envfiles.references/README.md, lines 1–3, likewise states that the script only readsGITHUB_TOKENfrom the environment and does not read an.envfile.
The retrieved credential is used as a bearer token for requests to the fixed GitHub API endpoints. The inspected code does not send the token to an unrelated recipie ...[truncated 1570 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the implicit
~/.openclaw/.envfallback and obtain the token exclusively fromos.environ.get("GITHUB_TOKEN"), matching the documented behavior. - If credential-file support is necessary, require an explicit command-line option such as
--token-fileand disclose the exact path before reading it. - Do not default to a shared application credential store. Restrict any supported token file to a user-selected path and validate that it is a regular file owned by the current user with restrictive permissions.
- Keep credentials out of output, errors, history records, and generated reports.
- Add tests verifying that the script does not access
~/.openclaw/.envduring normal execution. - Update
SKILL.mdandreferences/README.mdif the intended credential-loading behavior changes, ensuring the implementation and authorization documentation remain consistent.
- Remove the implicit
