T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:31- Finding
Unnecessary Authorization of a Fixed External IP Address
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:31-33,SKILL.md:157;references/credentials_guide.md:22-29;references/api_ref.md:85
Vulnerability Type: Violation of least privilege through an unnecessary network allowlist entry
Risk Level: MediumVulnerable Documentation
SKILL.md:31-33:markdown 2. **Add an IP allowlist entry** - On the same page, locate the IP allowlist settings - Add the server egress IP: `112.8.202.216` - Otherwise, the API will return error 40164Equivalent instructions are repeated in
references/credentials_guide.md:22-29, and the same address is presented as the solution for error 40164 inreferences/api_ref.md:85.Technical Analysis
The Skill directs every user to authorize the fixed external IP address
112.8.202.216in the WeChat account's API allowlist. However, the reviewed scripts make direct HTTPS requests from the local execution environment tohttps://api.weixin.qq.com. They do not use a proxy, hosted publishing service, callback, or other component associated with the documented fixed IP.Consequently, the address that normally needs authorization is the actual egress IP of the machine running the scripts, not an unexplained shared address. Adding the fixed address expands the account's trusted network boundary beyond what is required by the implementation.
This issue does not independently disclose credentials or grant immediate account access. Exploitation additionally requires possession of the account's AppID and AppSecret, an access token, or another applicable credential. Nevertheless, the instruction removes one layer of source-network restriction for requests originating from that address.
Attack Path
- A user follows the Skill's mandatory setup instructions.
- The user adds
112.8.202.216to the WeChat API allowlist. - The operator of that address, or an attacker who compromises infrastructure using it, gains ...[truncated 878 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every instruction that tells users to authorize
112.8.202.216. - Instruct users to determine the actual public egress IP of the environment where the Python scripts will run.
- Tell users to authorize only that address and to remove obsolete allowlist entries after infrastructure changes.
- If the fixed address belongs to an intended hosted service, clearly document:
- The service owner and operational purpose.
- Why local execution routes through that service.
- What credentials and content the service processes.
- Data retention and access-control policies.
- How users can avoid the hosted service.
- Make any hosted workflow explicitly optional rather than requiring all users to trust a shared external address.
- Add troubleshooting guidance that distinguishes local execution, dynamic egress IPs, NAT gateways, and intentionally hosted execution.
- Remove every instruction that tells users to authorize
