T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/install.sh:125- Finding
Root systemd service executes a user-writable binary
- Content
View full analysis
/tmp/xhs-mcp.service << SERVICEEOF [Unit] Description=Xiaohongshu MCP Service After=network.target [Service] WorkingDirectory=${INSTALL_DIR} ExecStart=${INSTALL_DIR}/xhs-mcp-bin server --port ${PORT} Restart=always RestartSec=5 [Install] WantedBy=multi-user.target SERVICEEOF sudo mv /tmp/xhs-mcp.service /etc/systemd/system/xhs-mcp.service sudo systemctl daemon-reload sudo systemctl enable xhs-mcp sudo systemctl start xhs-mcp ``` A corresponding unsafe example also appears in `SKILL.md:137-156`, where the service runs a binary from `/root/xiaohongshu-mcp` without an explicit `User=` directive. ### Technical Analysis The generated systemd unit does not specify `User=` or `Group=`, so systemd runs the service as root. In the executable installer, `INSTALL_DIR` is derived from the invoking user's `$HOME`: ```bash HOME_DIR="$HOME" INSTALL_DIR="$HOME_DIR/xiaohongshu-mcp" ``` The downloaded executable remains in that user-controlled directory. If an unprivileged user can replace or modify `xhs-mcp-bin`, the next systemd restart or system reboot causes systemd to execute the replacement with root privileges. This violates least privilege. The MCP server does not require root privileges merely to listen on port 18060, which is an unprivileged port. ### Attack Path 1. A user runs the installer and authorizes its `sudo` operations. 2. The installer registers `/etc/systemd/system/xhs-mcp.service`. 3. The unit points `ExecStart` to `${HOME}/xiaohongshu-mcp/xhs-mcp-bin`. 4. The service runs as root because no `User=` directive is present. 5. The user, malware running as that user, or another principal with write access replaces `xhs-mcp-bin`. 6. The attacker triggers `systemctl restart xhs-mcp ...[truncated 542 chars]- Remediation
View remediation
