T08 · Insecure Dependencies
- Location
INSTALL.md:190- Finding
Unverified Third-Party MCP Package Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
INSTALL.md, lines 190–199
Vulnerability Type: Third-party supply-chain execution without artifact integrity verification
Risk Level: MediumVulnerable Code
json { "mcpServers": { "playwright": { "command": "npx", "args": ["-y", "@playwright/mcp@0.0.78", "--browser", "chromium"], "disabled": false } } }The installation guide also recommends executing the package directly for validation:
text npx @playwright/mcp@0.0.78 --helpTechnical Analysis
The documented configuration invokes a third-party npm package through
npx. If the package is not already available locally,npxcan retrieve it and execute its lifecycle or runtime code from the npm supply chain.Pinning the package to version
0.0.78reduces uncontrolled version drift, but it does not independently establish artifact integrity or publisher trust. The documented process does not require an integrity hash, reviewed lockfile, vendored artifact, signature or provenance verification, or inspection of the resolved transitive dependency tree. The-yargument also suppresses the normal installation confirmation.Because the package runs as an MCP server with browser automation functionality, compromised package code would execute with the operating-system privileges of the host process. Its effective access would depend on the host's MCP sandboxing, filesystem permissions, browser profile, network policy, and tool authorization settings.
Attack Path
- An attacker compromises the specified npm package release, its publisher account, a transitive dependency, or the package-resolution infrastructure.
- A user follows the installation guide and configures the host to launch
npx -y @playwright/mcp@0.0.78. npxretrieves and executes the compromised package or dependency.- Malicious code runs under the installing user's account ...[truncated 1254 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace ad hoc
npxexecution with a reviewed installation process using a committed lockfile and integrity-pinned dependency resolution. - Verify npm provenance, publisher identity, package signatures where available, and the resolved artifact checksum before execution.
- Review and pin transitive dependencies rather than relying only on the top-level package version.
- Remove
-yfrom recommended interactive setup commands so users receive an explicit execution prompt. - Prefer a locally installed, reviewed package invoked with installation disabled, such as
npx --no-install, after integrity verification. - Run the MCP server in a sandbox or dedicated low-privilege account with a restricted filesystem view and outbound-network allowlist.
- Use a dedicated browser profile without saved credentials, authenticated sessions, payment information, or unrelated browsing data.
- Restrict MCP permissions to the minimum browser and output-directory access required for public regulatory-source retrieval.
- Document an approved package hash, verification procedure, update policy, and rollback process.
- Reassess the package and its dependency tree whenever the pinned version is changed.
- Replace ad hoc
