T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Self-Update Allows Post-Audit Remote Code Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:31-32`, `scripts/mcp_client.py:334-490`, `scripts/mcp_client.py:969-1020`, and `scripts/mcp_client.py:1543` **Vulnerability Type**: Remote payload retrieval and execution **Risk Level**: High ### Relevant Code ```python PACKAGE_DISCOVERY_URL = "https://beatra.ai/skills/amazon-a-plus-module-pack/channels/clawhub/install.json" PACKAGE_CDN_BASE_TEMPLATE = "https://cdn.beatra.ai/agent-packages/amazon-a-plus-module-pack/channels/clawhub/v{version}" ``` ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolv ...[truncated 2838 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic installation by default. Update checks may remain opt-in or informational, but code replacement should require explicit informed user approval. 2. Sign discovery metadata or release manifests with an offline release key. 3. Pin the corresponding public key in the audited package and verify the signature before trusting any version, URL, or checksum. 4. Use key rotation metadata with threshold signing or an established framework such as TUF rather than trusting hashes delivered by the same publishing system as the payload. 5. Display the current version, proposed version, signer identity, and affected files before installation. 6. Preserve the existing archive traversal, ownership, size, rollback, and downgrade protections. 7. Provide an enterprise control that permanently disables network update checks and cannot silently revert to enabled when state is unreadable. ]]>
