T05 · Unauthorized Access and Privilege Escalation
- Location
lib/runner.js:47- Finding
Persistent Full-Tool Worker Inherits External-Service Credentials and Administrator Access
- Content
View full analysis
0 && list[0].authProfiles) { newAgent.authProfiles = list[0].authProfiles; } const newList = [...list, newAgent]; const patchParams = { raw: JSON.stringify({ agents: { list: newList } }, null, 2) }; if (snapshot.hash) patchParams.baseHash = snapshot.hash; await gateway.call('config.patch', patchParams); ``` ```js // lib/gateway.js:79-94 const token = this.config.gateway.auth.token; this.ws.send(JSON.stringify({ type: 'req', id: String(++this.requestId), method: 'connect', params: { minProtocol: 3, maxProtocol: 3, client: { id: 'cli', version: '2026.2.9', platform: 'linux', mode: 'cli' }, role: 'operator', scopes: ['operator.read', 'operator.write', 'operator.admin'], caps: [], commands: [], permissions: {}, auth: { token }, ``` ```js // lib/runner.js:78-85 const soulPath = `${stateDir}/agents/${WORKER_AGENT_ID}/SOUL.md`; const agentDir = `${stateDir}/agents/${WORKER_AGENT_ID}`; // Create agent dir and write SOUL.md via filesystem const fsMod = await import('fs'); fsMod.default.mkdirSync(agentDir, { recursive: true }); fsMod.default.writeFileSync(soulPath, WORKER_SOUL); ``` ### Technical Analysis SoulFlow authenticates with the gateway using operator administrator scopes and creates a persistent worker configured with the unrestricted `full` tool profile. It then copies ...[truncated 2139 chars]- Remediation
View remediation
