T05 · Unauthorized Access and Privilege Escalation
- Location
index.js:35- Finding
Unauthenticated Tool API Permits Credential Theft and Unauthorized Game Control
- Content
View full analysis
{ const parsed = requestSchema.safeParse(req.body ?? {}); ``` ```js async function bootstrap() { await loadApiCodeStore(); app.listen(port, () => { console.log(`skill-openclaw listening on :${port}`); }); } ``` ### Technical Analysis The common `/tool/:name` handler has no authentication or authorization middleware. Payload validation through Zod only validates request structure; it does not establish the caller's identity or determine whether the caller is authorized to access a cache key or mining session. In addition, `app.listen(port)` does not explicitly bind the service to a loopback address. Under Node.js, omitting the host can expose the service on available network interfaces, depending on the deployment environment. Consequently, any client with network access to the listening port can invoke sensitive tools. The exposed operations include: - Reading, replacing, and deleting stored API credentials - Purchasing stamina with in-game diamonds - Starting managed mining sessions - Force-restarting or stopping an existing mining session - Reading full mining status and session events The optional `cacheKey` is caller-controlled and is not an authorization mechanism. The predictable default value, `default`, further reduces the effort required to access the primary stored credential. ### Attack Path 1. An attacker identifies a reachable deployment of the service on its default TCP port, `4021`, or another configured port. 2. The attacker sends an unauthenticated request to: ```http POST /tool/get_api_code Content-Type: application/json {"cacheKey":"default"} ``` 3. If a credential has been stored under the default key, the service returns the reusable `apiCode`. 4 ...[truncated 1015 chars]- Remediation
View remediation
