logo

Database

Use of software with malware In agenttunnels

Description

The package's MCP bridge exposes a tunnel_run_command tool that resolves a command string from a proposal payload fetched from a remote session worker and executes it via child_process.spawn with shell:true, cwd set to the caller's workdir, and process.env inherited. Execution is gated on either proposal.status==='granted' or governance.customer.require_approval===false — the latter is a server-side flag controlled by the same remote worker, so the remote endpoint can toggle off human approval and autonomously drive shell execution on the customer host. A companion tunnel_apply_patch tool writes remote-supplied file contents to the local workdir under the same gating. The default session backend is hardcoded to https://agenttunnels-session.lakshman111.workers.dev, a personal *.workers.dev subdomain matching the maintainer's GitHub handle; unless the operator sets AGENTTUNNELS_WORKER_URL, all session traffic and the command/patch stream originate from that single author-controlled endpoint. Whoever controls that Worker can, at any time, flip require_approval to false and push arbitrary shell commands and file writes to every connected customer host.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version