T05 · Unauthorized Access and Privilege Escalation
- Location
src/index.js:359- Finding
Unauthenticated Network Access Enables Remote Control of the XiaoHongShu Account
- Content
View full analysis
Vulnerability Details
File Location:
src/index.js:30-31,src/index.js:359-365, andsrc/index.js:408
Additional Affected Entry Points:src/index-fixed.js:29,src/index-fixed.js:231-246,src/index-fixed.js:273;src/index-sse.js:30,src/index-sse.js:151-157,src/index-sse.js:186
Vulnerability Type: Missing authentication and authorization on a network-exposed MCP service
Risk Level: CriticalVulnerable Code
js const PORT = process.env.XHS_PORT || 18060; const HOST = process.env.XHS_HOST || '0.0.0.0';js // Handle all /mcp requests app.all('/mcp', async (req, res) => { console.error(`\n收到请求: ${req.method} ${req.url}`); console.error('Content-Type:', req.headers['content-type']); console.error('Accept:', req.headers.accept); try { await transport.handleRequest(req, res);js app.listen(PORT, HOST, () => {Technical Analysis
The MCP server binds to
0.0.0.0by default, making it reachable through every network interface available to the host. The/mcproute forwards requests directly to the MCP transport without verifying an API key, bearer token, client certificate, session, source address, or user authorization.The registered tools include sensitive and state-changing operations such as:
delete_cookieslike_feedfavorite_feedpost_comment_to_feedreply_comment_in_feedpublish_contentpublish_with_video
These operations execute through a browser carrying the victim's saved XiaoHongShu authentication cookies. Possession of an
xsec_tokenfor individual content does not authenticate the caller to this local service and does not protect tools such as publishing or deleting cookies.The same access-control weakness is present in the alternate HTTP and SSE server implementations.
Attack Path
- A victim starts the service using its default configuration.
- The service liste ...[truncated 1138 chars]
- Remediation
View remediation
Remediation Suggestions
- Change the default binding address to
127.0.0.1or::1. - Require a cryptographically strong bearer token, mutual TLS, or another authenticated transport before dispatching any MCP request.
- Compare tokens using constant-time logic and load credentials from a protected secret store.
- Implement authorization policies that distinguish read-only tools from account-changing tools.
- Require explicit user confirmation for publishing, commenting, cookie deletion, and other destructive operations.
- Restrict access at the host firewall or reverse proxy and do not expose the port directly to untrusted networks.
- Add request rate limiting, security event logging, request-size limits, and origin or host validation.
- Apply equivalent controls to
index-fixed.js,index-sse.js, andindex-progressive.js. - Document that remote exposure is unsupported unless authentication and TLS are configured.
- Change the default binding address to
