T09 · Insecure Skill Coding Practices
- Location
DEPLOY.md:29- Finding
Privileged MCP Service Exposed on All Network Interfaces Without a Documented Authentication or TLS Boundary
- Content
View full analysis
Vulnerability Details
File Location:
DEPLOY.md:29-36
Vulnerability Type: Unauthenticated exposure of a credential-backed DevOps service over plaintext HTTP
Risk Level: HighVulnerable Code
yaml ports: - "3000:3000" env_file: - .env restart: unless-stopped command: node dist/index.js --sse healthcheck: test: ["CMD", "wget", "-q", "--spider", "--timeout=5", "http://localhost:3000/sse"]The deployment documentation also configures the container with Alibaba Cloud credentials:
yaml ALIBABA_CLOUD_ACCESS_KEY_ID=<your_access_key_id> ALIBABA_CLOUD_ACCESS_KEY_SECRET=<your_access_key_secret> ALIBABA_CLOUD_REGION=cn-hangzhouTechnical Analysis
Docker Compose port syntax of
"3000:3000"publishes the container port on all host interfaces by default. Consequently, the MCP SSE endpoint may be reachable from other systems whenever host firewall and network routing rules permit it.The documented architecture uses plaintext HTTP, and the reviewed client does not supply an authentication token or other client credential when opening the SSE connection or submitting JSON-RPC messages. The deployment configuration also does not place the service behind an authenticated reverse proxy or a TLS termination layer.
This service is particularly sensitive because the container receives Alibaba Cloud RAM AccessKey credentials and exposes tools that can access or modify Yunxiao projects, work items, pipelines, repositories, files, and deployment resources. The effective permissions available through the exposed endpoint are determined by the RAM identity configured in
.env.Attack Path
- An operator follows
DEPLOY.mdand publishes host port 3000 using"3000:3000". - The host is connected to a shared LAN, cloud network, VPN, or public interface where another party can reach TCP port 3000.
- An attacker connects to the plaint ...[truncated 1476 chars]
- An operator follows
- Remediation
View remediation
Remediation Suggestions
-
Bind the published service exclusively to loopback when it is intended for local use:
yaml ports: - "127.0.0.1:3000:3000" -
If remote access is required, avoid publishing the MCP service directly. Place it behind a hardened reverse proxy or gateway that provides:
- TLS with certificate validation.
- Strong client authentication, preferably mutual TLS or short-lived identity tokens.
- Authorization policies controlling which identities may invoke individual tools.
- Request size limits, rate limits, and audit logging.
- Network allowlists or private-network access controls.
-
Update the client to require HTTPS for non-loopback addresses and to reject insecure remote HTTP endpoints by default.
-
Use a dedicated, least-privileged RAM identity. Grant only the Yunxiao actions and resources required for the intended workflow, and separate read-only from mutating deployments where practical.
-
Restrict inbound port 3000 through host and cloud firewalls. Verify from another network host that the endpoint is not unintentionally reachable.
-
Rotate the AccessKey if the service was previously exposed to an untrusted network, and review Yunxiao and cloud audit logs for unauthorized operations.
-
