Privilege Escalation to Proxy Admin via Cross-Domain Reuse of the Salt Key
Affected versions
Patched versions
Summary
An authenticated user with internal_user privileges can escalate to proxy_admin and achieve remote code execution. The proxy uses one encryption key for two purposes: sealing secrets at rest and minting session tokens. An attacker exploits this by requesting a new API key with a crafted metadata field containing a forged admin credential as the "secret" value. The proxy encrypts and returns this payload. When this value is then presented as a bearer token, the proxy decrypts it, trusts the forged admin identity, and grants full administrative access, including the ability to execute arbitrary commands via the MCP stdio endpoint.
Affected versions
Versions later than 1.91.0 are exploitable in the default configuration. Versions 1.87.0 through 1.90.x are exploitable only if EXPERIMENTAL_UI_LOGIN=true was explicitly set.
Mitigation
Upgrade to a patched version as soon as possible.
If you cannot upgrade immediately, set EXPERIMENTAL_UI_LOGIN=false. This disables the vulnerable authentication path but also breaks CLI SSO and Claude Code gateway login.
Impact
An internal user can escalate to proxy admin and execute arbitrary commands on the host.
Discovery Credit: Hoa X. Nguyen (OPSWAT Unit 515)