T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Automatic Updates Permit Post-Audit Remote Code Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1018` **Vulnerability Type**: Silent remote payload retrieval and installation without an independent signature trust root **Risk Level**: High ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_update(discovery, get_bytes=get_bytes) _apply_update( install_root=r ...[truncated 2333 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic installation by default; require explicit, informed user approval before replacing code. 2. Separate update checking from update installation. 3. Sign release metadata and manifests with an offline or otherwise strongly protected publisher key. 4. Embed or securely provision the verification public key independently of the mutable discovery response. 5. Verify signatures before trusting versions, URLs, manifests, or hashes. 6. Preserve the existing path, archive-size, file-size, rollback, and downgrade protections. 7. Display the target version and verified signer identity before installation. 8. Consider distributing immutable, reviewed package versions through the host platform rather than implementing in-package self-replacement. ]]>
