T08 · Insecure Dependencies
- Location
README.md:76- Finding
Unpinned Third-Party MCP Server Package Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
README.md:76
Vulnerability Type: Unpinned dependency execution and supply-chain exposure
Risk Level: MediumVulnerable Code Snippet:
bash codex mcp add drawio -- npx -y @next-ai-drawio/mcp-server@latestTechnical Analysis
The documented installation command uses
npxwith the mutable@latesttag and the-yoption. This causes npm to retrieve and execute whichever release is identified as the latest version at installation time, without requiring interactive confirmation.Because neither an exact package version nor an integrity value is specified, the executed code can differ from the code that was available when this skill was audited. This weakens reproducibility and creates a supply-chain trust boundary around the npm package, its maintainers, the associated publishing account, the npm registry, and its transitive dependencies.
The audit found no evidence that the currently named package is malicious. The vulnerability is the unsafe dependency acquisition pattern: a future compromised, malicious, or unexpectedly incompatible release could be downloaded and executed automatically.
Attack Path
- An attacker compromises the npm package, a maintainer or publishing account, the package namespace, or a transitive dependency.
- The attacker publishes a malicious version that becomes the target of the
latestdistribution tag. - A user follows the setup instructions in
README.md. npx -ydownloads the attacker-controlled release without requesting package-installation confirmation.- npm installation hooks or the MCP server entry point execute with the privileges of the user running Codex.
- Malicious code can access resources available to that account and may continue operating whenever the configured MCP server is subsequently launched.
Impact Assessment
Successful exploitation could provide arbitrary code execution under t ...[truncated 587 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace
@latestwith an exact, reviewed package version, for example:bash codex mcp add drawio -- npx -y @next-ai-drawio/mcp-server@X.Y.ZSubstitute
X.Y.Zwith a version that has been independently reviewed and tested. -
Document the package's authoritative source repository and npm publisher so users can verify provenance before installation.
-
Maintain a lockfile or another integrity-controlled installation mechanism where the surrounding deployment model supports it. Pin transitive dependencies and verify registry integrity metadata.
-
Review package lifecycle scripts and the MCP server entry point before approving version upgrades. Treat each upgrade as a new code-execution trust decision.
-
Avoid recommending automatic acceptance through
npx -ywhere interactive review is practical. If-yremains necessary for automation, pair it with exact version pinning and integrity verification. -
Run the MCP server with least privilege in an isolated environment. Restrict filesystem and network access to the minimum required for diagram operations.
-
Establish a controlled update process that tests and approves newer versions before changing the documented pin.
-
