T05 · Unauthorized Access and Privilege Escalation
- Location
project/src/session.ts:22- Finding
Automatic Approval Bypasses Per-Application and Sensitive Capability Authorization
- Content
View full analysis
Vulnerability Details
File Location:
project/src/session.ts:22-46andproject/src/session.ts:67
Vulnerability Type: Authorization bypass and excessive privilege granting
Risk Level: HighVulnerable Code:
ts function autoApprovePermission(req: CuPermissionRequest): CuPermissionResponse { const granted = req.apps .filter(app => app.resolved && !app.alreadyGranted) .map(app => ({ bundleId: app.resolved!.bundleId, displayName: app.resolved!.displayName, grantedAt: Date.now(), tier: app.proposedTier, })) const denied = req.apps .filter(app => !app.resolved) .map(app => ({ bundleId: app.requestedName, reason: 'not_installed' as const, })) return { granted, denied, flags: { ...DEFAULT_GRANT_FLAGS, ...req.requestedFlags, }, } }ts onPermissionRequest: async req => autoApprovePermission(req),Technical Analysis
The MCP computer-use framework includes a permission-request workflow intended to authorize access to individual applications and sensitive capabilities. The standalone session replaces interactive authorization with
autoApprovePermission().Every requested application that resolves to an installed application is granted its proposed access tier without user review. In addition,
req.requestedFlagsis merged over the secure defaults. This allows requests for capabilities such as clipboard reading, clipboard writing, and system-level key combinations to be approved automatically.macOS Accessibility and Screen Recording permissions still provide an operating-system boundary. However, once the user has granted those broad TCC permissions to the runtime, this implementation provides no meaningful per-application or per-capability consent boundary. The existing access-control framework therefore appears to enforce permission tiers while its ...[truncated 1990 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
autoApprovePermission()with an interactive approval handler that shows:- The exact application and bundle identifier.
- The proposed access tier.
- Requested clipboard and system-key capabilities.
- The reason supplied by the requesting client.
- Require explicit user confirmation before granting a new application or increasing an existing application's tier.
- Keep
clipboardRead,clipboardWrite, andsystemKeyCombosdisabled unless individually approved. - Maintain and enforce a user-denied application list rather than returning an empty list for every session.
- If unattended operation is required, provide a disabled-by-default mode backed by a static, user-managed allowlist containing exact bundle identifiers, maximum tiers, and allowed flags.
- Prevent unattended mode from granting applications or capabilities absent from that allowlist.
- Record security-relevant grant events locally without recording clipboard or screen contents.
- Add tests demonstrating that new applications, privilege-tier increases, clipboard access, and system-key requests remain denied until explicitly authorized.
- Replace
