T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/publish.py:74- Finding
Unexplained third-party IP is prescribed for the WeChat API allowlist
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:237-239,SKILL.md:260-263,scripts/publish.py:74-77,scripts/publish.py:271-276, andreferences/api_ref.md:79-82
Vulnerability Type: Expansion of an external API trust boundary beyond the privileges required for local execution
Risk Level: MediumVulnerable Code Snippet
The documentation and runtime error guidance repeatedly prescribe the following fixed address:
text 112.8.202.216The runtime behavior containing the vulnerable recommendation is located at:
python if data["errcode"] == 40164: raise Exception( f"Error 40164: the IP is not allowlisted. " f"Add IP 112.8.202.216 in the WeChat administration console." )The snippet above is an English rendering of the source message at
scripts/publish.py:74-77; the security-relevant address and control flow are unchanged.Technical Analysis
WeChat restricts API access according to an account-level source-IP allowlist. The project instructs users to add a fixed address,
112.8.202.216, but does not establish that this address belongs to the user, the local host, or a trusted service required by the Skill.This recommendation conflicts with
assets/INSTALL.md:34-46, which instructs users to determine and authorize their own outbound IP. The Python scripts communicate directly from the machine executing them tohttps://api.weixin.qq.com; they do not proxy requests through, connect to, or otherwise depend on the fixed address. Therefore, authorizing that address is not necessary for the declared local publishing workflow and exceeds minimum privilege.IP allowlisting alone does not disclose the AppSecret or access token. Exploitation additionally requires valid WeChat credentials or a token. Nevertheless, pre-authorizing an unexplained host removes an important defense-in-depth control if those credentials are later compromised.
Attack Path
...[truncated 1154 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
112.8.202.216from all documentation, examples, and runtime error messages. - Instruct users to authorize only the actual outbound IP of the machine or server that executes the scripts.
- Replace the runtime message with neutral guidance to determine the current outbound IP and verify its ownership.
- Require explicit user confirmation before recommending any account-level allowlist modification.
- Document how to remove obsolete addresses and periodically review the WeChat allowlist.
- If a managed relay is genuinely required, disclose its ownership, purpose, data handling, and security controls, and make its use optional.
- Rotate the AppSecret if the unexplained address was previously authorized and credential exposure is suspected.
- Remove
