OpenClaw出现「自我攻击」漏洞:误执行Bash命令致密钥泄露

BlockBeats 消息,3 月 5 日,Web3 安全公司 GoPlus 发文称,AI 开发工具 OpenClaw 近日被曝出现一次「自我攻击」安全事件。在执行自动化任务时,系统在调用 Shell 命令创建 GitHub Issue 过程中构造了错误的 Bash 指令,意外触发命令注入,导致大量敏感环境变量被公开。

事件中,AI 生成的字符串包含反引号包裹的 set,被 Bash 解释为命令替换并自动执行。由于 Bash 在无参数执行 set 时会输出当前所有环境变量,最终导致超过 100 行敏感信息(包括 Telegram 密钥、认证 Token 等)被直接写入 GitHub Issue 并公开发布。

GoPlus 建议,在 AI 自动化开发或测试场景中,应尽量使用 API 调用替代直接拼接 Shell 命令,并遵循最小权限原则隔离环境变量,同时禁用高风险执行模式,并在关键操作中引入人工审核机制。

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

Scammers Impersonating Iranian Officials Demand Bitcoin and USDT from Ships in Strait of Hormuz

Gate News message, April 21 — Scammers posing as Iranian officials are demanding Bitcoin (BTC) and Tether (USDT) as transit fees from ships in the Strait of Hormuz, according to a warning from MARISKS, a Greece-based maritime risk management firm. The scheme falsely promises "safe transit

GateNews8u geleden

Crypto Hack Draining $300M May Slow Wall Street's Blockchain Ambitions

Gate News message, April 21 — A weekend hack that drained nearly $300 million from a small crypto project and triggered a $10 billion run on the largest decentralized lending platform may slow Wall Street's growing interest in blockchain technology, according to a report from Jefferies LLC released

GateNews8u geleden

Security Researcher Discloses CometBFT 0-day Vulnerability; Direct Asset Theft Not Possible

Gate News message, April 21 — Security researcher Doyeon Park disclosed a critical 0-day vulnerability (CVSS 7.1) in CometBFT, the consensus layer of Cosmos, according to a post on X. The flaw could cause network nodes to stall during block synchronization, disrupting system operations, but cannot d

GateNews11u geleden

Fake Police Impersonators Force French Couple to Transfer Nearly $1M in Bitcoin

Criminals posing as police in France coerced a couple to transfer nearly $1M in Bitcoin, using fear and authority in a 'wrench attack' that exploits people, not wallets. Abstract: Attackers used impersonation and psychological coercion to force a Bitcoin transfer, illustrating a wrench attack that targets human vulnerability rather than technical wallet exploits.

GateNews12u geleden

Armed Robbery Attempt on French Crypto Professional Thwarted; Suspect Arrested

Gate News message, April 21 — A 40-year-old crypto industry professional in Saint-Jean-de-Védas, near Montpellier, France, thwarted an armed robbery attempt at his home. The suspect, disguised as a delivery person, entered the residence and demanded the victim hand over cryptocurrency wallet

GateNews12u geleden
Opmerking
0/400
Geen opmerkingen