🔴 [P0] Implement capability enforcement for federation commands #273

Closed
opened 2026-02-03 22:29:21 +00:00 by jason.woltje · 0 comments
Owner

Summary

Commands from remote instances execute without checking if connection has required capabilities. Privilege escalation vulnerability.

Location

apps/api/src/federation/federation-agent.service.ts:189-230

Security Impact

  • Remote instances can execute ANY command type
  • Capability system is cosmetic only
  • Privilege escalation via capability bypass

Required Fix

Check connection.remoteCapabilities before executing commands.

Priority

CRITICAL (P0) - Authorization bypass

## Summary Commands from remote instances execute without checking if connection has required capabilities. Privilege escalation vulnerability. ## Location `apps/api/src/federation/federation-agent.service.ts:189-230` ## Security Impact - Remote instances can execute ANY command type - Capability system is cosmetic only - Privilege escalation via capability bypass ## Required Fix Check `connection.remoteCapabilities` before executing commands. ## Priority **CRITICAL (P0)** - Authorization bypass
jason.woltje added the securityp0apiapi labels 2026-02-03 22:29:21 +00:00
jason.woltje added this to the M7.1-Remediation (0.0.8) milestone 2026-02-03 22:31:44 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaic/stack#273