Skip to content

gl(mcp): ucan_delegate panics on overflow expiry and ucan_verify ignores nbf #494

Description

@euxaristia

Summary

The MCP ucan_delegate tool computes chrono::Utc::now() + chrono::Duration::hours(h) with an arbitrary i64 from tool arguments (crates/gl/src/mcp.rs:1132-1135); chrono panics on overflow, and the panic unwinds the serve loop, killing the whole MCP process and all tools until restart. The tool arguments are steerable by prompt injection through untrusted repo/issue text read via other tools. Related: ucan_verify reports valid: sig_valid && !expired and ignores not-before (mcp.rs:1158-1175), so a not-yet-valid token shows as valid to the agent. The same overflow exists in the CLI at crates/gl/src/ucan_cmd.rs:88 (user-supplied only).

Impact

One crafted expiry_hours value takes down the MCP server (availability of all tools); the nbf miss misreports token validity to agent decision loops.

Remediation

  1. Use checked_add_signed (or clamp the range) for expiry arithmetic in both MCP and CLI paths.
  2. Include nbf in ucan_verify's validity result.

Proposed labels: kind:bug, crate:gl, subsystem:identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions