Skip to content

gl: ETH private key and UCAN token accepted as command-line arguments #480

Description

@euxaristia

Summary

gl name register takes the wallet-controlling --private-key as a plain string argument (also via ETH_PRIVATE_KEY env, crates/gl/src/name.rs:67-68, :109), and gl task create takes --ucan_token (crates/gl/src/task.rs:37), which is sent in the task JSON (task.rs:164) and stored by the node (gitlawb-node/src/api/tasks.rs:40,83,113).

Impact

Command-line arguments are visible process-wide (process listings, WMI, shell history). The wallet key is the direct concern; the UCAN token is additionally persisted in task records readable through the feed (see #268). The node's iss == signer check (auth/mod.rs:281) prevents replay as the delegator, so this is capability-graph disclosure rather than immediate privilege. #354/#459 cover the file-permission channel; this is the argv channel.

Remediation

  1. Read the private key from a file or hidden prompt instead of argv.
  2. Prefer the stored UCAN from ucan.json over a flag; document argv as unsupported.

Proposed labels: kind:security, crate:gl, subsystem:identity.

Activity

  1. added
    crate:glgl — the contributor CLI
    kind:securityVulnerability fix or hardening
    sev:highMajor break or real security/trust risk, no easy workaround
    subsystem:identityDID/UCAN, http-sig auth, push authorization
    subsystem:visibilityPath-scoped visibility and content withholding
    sev:mediumDegraded but workaround exists
    and removed
    subsystem:visibilityPath-scoped visibility and content withholding
    sev:highMajor break or real security/trust risk, no easy workaround
    on Sep 26, 2026
  2. beardthelion commented on Sep 26, 2026

    @beardthelion
    Collaborator

    Recalibrating to sev:medium. The disclosure channel is local (process listings, shell history), the same class as #354's secret-file exposure rather than a remote trigger. The wallet key is the worst case and still argues for a prompt fix, but local-only disclosure sits at medium. Also dropping subsystem:visibility, which covers content withholding rather than credential handling.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions