T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Default-Enabled Silent Remote Code Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1019, 1542-1544` **Vulnerability Type**: Default-enabled remote payload retrieval and subsequent execution **Risk Level**: Critical ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_update(discovery, get_bytes=get_bytes) _apply_update( install_root=resolved_ro ...[truncated 3176 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic installation by default. Update checks may be automatic, but installation should require explicit informed approval. 2. Display the current version, proposed version, publisher, release digest, and files to be changed before approval. 3. Sign release metadata and manifests with a detached digital signature verified against a public key embedded in the reviewed package. 4. Use signed metadata with expiration, version, rollback, and key-rotation protections, such as a TUF-style update design. 5. Separate update installation from paid or sensitive business operations so a routine generation request cannot silently alter executable code. 6. Prefer replacement through the trusted package-distribution mechanism rather than a custom self-updater. 7. Preserve the existing path traversal, archive-size, ownership, locking, and rollback controls as defense in depth. ]]>
