T05 · Unauthorized Access and Privilege Escalation
- Location
src/http-server.ts:197- Finding
Unauthenticated Network-Accessible Telegram MCP API
- Content
View full analysis
{ log(`HTTP server listening on port ${HTTP_PORT}`); log(`MCP endpoint: http://localhost:${HTTP_PORT}/mcp`); log(`Status endpoint: http://localhost:${HTTP_PORT}/status`); log('Waiting for browser to connect to telebiz-mcp...'); }); ``` ### Technical Analysis The `/mcp` endpoint forwards caller-controlled JSON-RPC methods and parameters to the MCP subprocess without authenticating the caller or authorizing the requested tool. Calling `server.listen(HTTP_PORT)` without a host normally binds the service to all available interfaces, not only localhost. This conflicts with the log output and documentation, which present the endpoint as local. In addition, `Access-Control-Allow-Origin: *` permits requests from arbitrary browser origins where the browser's local-network security policy allows them. The exposed MCP tool set includes operations that read private messages and perform destructive or externally visible actions, such as sending messages, forwarding messages, deleting messages, deleting chats, re ...[truncated 1477 chars]- Remediation
View remediation
{ // ... }); ``` 2. Prefer a Unix domain socket when only local processes require access. 3. Require a cryptographically random bearer token for every MCP request. 4. Compare authentication values using a timing-safe comparison. 5. Remove wildcard CORS. Reject browser origins by default or allow only a narrowly configured trusted origin. 6. Validate both `Host` and `Origin` headers. 7. Implement a server-side tool allowlist and per-tool authorization. 8. Require explicit user confirmation for destructive tools. 9. Return proper HTTP 401 and 403 responses for unauthenticated and unauthorized requests. 10. Document that non-local exposure requires TLS, network filtering, and strong client authentication. ]]>
