T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:79- Finding
Unauthenticated Bidder Can Become the Task Recipient
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 79–91
Vulnerability Type: Missing bidder authentication and authorization
Risk Level: Highbash while [ $(($(date +%s) - START_TIME)) -lt $AUCTION_DURATION ]; do pilotctl --json inbox | jq ".[] | select(.data.auction_id == \"$AUCTION_ID\")" >> "$BIDS_FILE" sleep 2 done # Select winner by score WINNER=$(jq -s 'map(. + {score: (1 - (.data.price / 100)) * 0.5 + .data.quality_guarantee * 0.5}) | sort_by(-.score) | .[0]' "$BIDS_FILE") WINNER_ADDR=$(echo "$WINNER" | jq -r '.sender') WINNER_PRICE=$(echo "$WINNER" | jq -r '.data.price') # Award task pilotctl --json task submit "$WINNER_ADDR" --task "video-transcoding: $TASK_SPEC"Technical Analysis
The workflow accepts any inbox entry whose
auction_idmatches the current auction. It does not verify the sender's identity, message signature, eligibility, or authorization. It also does not validate the types and permitted ranges ofpriceandquality_guarantee.The sender address from the highest-scoring untrusted message is assigned directly to
WINNER_ADDR. The workflow then sends$TASK_SPECto that address without requester confirmation. Consequently, possession or prediction of the auction identifier is treated as sufficient authorization to participate and potentially receive the task.Attack Path
- An attacker observes or predicts the timestamp-derived auction identifier.
- The attacker sends an inbox message containing that
auction_id. - The attacker supplies bid values designed to maximize the scoring expression, such as an abnormally low or negative price and a high quality guarantee.
- The collector accepts the message because it filters only by
auction_id. - The scoring operation ranks the malicious bid first.
- The attacker's sender address becomes
WINNER_ADDR. pilotctl task submittransmits the task and$TASK_SPECto the attacker-contro ...[truncated 650 chars]
- Remediation
View remediation
Remediation Suggestions
- Verify each bid's protocol-level digital signature and bind the verified identity to the sender address.
- Limit participation to registered or explicitly approved bidder identities.
- Use a cryptographically random, high-entropy auction nonce instead of relying solely on a timestamp-derived identifier.
- Validate bids against a strict schema before scoring them. Require finite numeric values and enforce reasonable minimum and maximum ranges for price and quality.
- Reject duplicate, expired, malformed, and replayed bids.
- Confirm that the selected sender remains authorized immediately before submitting the task.
- Require explicit requester approval before transmitting sensitive task specifications.
- Minimize the information sent during task assignment and transfer sensitive data only over an authenticated, encrypted channel.
- Handle the no-valid-bid case explicitly rather than allowing an empty or malformed winner value to reach
pilotctl.
