T05 · Unauthorized Access and Privilege Escalation
- Location
project/src/session.ts:21- Finding
Application-control permissions are silently auto-approved
- Content
View full analysis
Vulnerability Details
File Location:
project/src/session.ts, lines 21–48 and 64
Vulnerability Type: Authorization and user-consent bypass
Risk Level: HighVulnerable Code
ts function autoApprovePermission(req: CuPermissionRequest): CuPermissionResponse { const granted = req.apps .filter(app => app.resolved && !app.alreadyGranted) .map(app => ({ bundleId: app.resolved!.bundleId, displayName: app.resolved!.displayName, grantedAt: Date.now(), tier: app.proposedTier, })) const denied = req.apps .filter(app => !app.resolved) .map(app => ({ bundleId: app.requestedName, reason: 'not_installed' as const, })) return { granted, denied, flags: { ...DEFAULT_GRANT_FLAGS, ...req.requestedFlags, }, } } // ... onPermissionRequest: async req => autoApprovePermission(req),Technical Analysis
The MCP interface presents
request_accessas a user-consent boundary. Its tool description states that the user sees a dialog listing requested applications and can allow or deny the request. The request-processing code also forwards application and permission requests throughonPermissionRequest.The standalone session implementation defeats that boundary by connecting
onPermissionRequestdirectly toautoApprovePermission. This function grants every resolved application that is not already granted and merges all caller-requested flags into the session's grant flags. There is no interactive prompt, external policy check, or affirmative user decision.An MCP client or agent controls:
- The requested application names.
- The displayed reason.
- The
clipboardReadpermission request. - The
clipboardWritepermission request. - The
systemKeyCombospermission request.
Once approved, the response is merged into session state by the MCP server's permission wrapper, allowing subsequent desktop-control operations. Application-tier and policy gates re ...[truncated 1753 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
autoApprovePermissionwith a genuine user-facing approval handler that displays every newly requested application and permission flag. - Require an explicit affirmative user response before adding application grants or enabling clipboard and system-key permissions.
- Default to denial when no interactive permission handler is available.
- Treat each permission flag independently; never merge caller-requested flags directly into session state without validation.
- Preserve application tier and policy checks as defense in depth, but do not use them as a substitute for user consent.
- If unattended trusted-local automation is required, place it behind an explicit configuration established outside MCP-controlled arguments. Disable it by default and clearly expose its state to the user.
- Update the tool description and documentation so the stated approval behavior exactly matches the implemented runtime behavior.
- Add tests verifying that unresolved, denied, cancelled, and unattended permission requests cannot create grants or enable sensitive flags.
- Replace
