T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Self-Update Permits Remotely Controlled Code Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1020`, `scripts/mcp_client.py:1542-1544`; related update trust validation at `scripts/mcp_client.py:299-328` and `scripts/mcp_client.py:469-491` **Vulnerability Type**: Silent remote payload retrieval and execution **Risk Level**: High ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_upda ...[truncated 4211 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic installation by default. Permit silent update checks, but require explicit user approval before replacing code. 2. Sign discovery metadata and release manifests with an offline-controlled package-signing key. 3. Embed or securely pin the corresponding public key in the reviewed package. 4. Verify the signature before trusting the version, URLs, hashes, package identity, channel, or locale. 5. Implement signed rollback protection so a compromised endpoint cannot advertise an older vulnerable release. 6. Separate checking, downloading, and installation into explicit stages with clear user-visible status. 7. Preserve the existing path validation, size restrictions, owned-file checks, transactional replacement, and rollback safeguards. ]]>
