T05 · Unauthorized Access and Privilege Escalation
- Location
lib/employees.mjs:48- Finding
Organization-Wide Employee Directory Collection Exceeds Name-Resolution Requirements
- Content
View full analysis
Vulnerability Details
File Location:
lib/employees.mjs, lines 48-77
Vulnerability Type: Excessive directory access and unnecessary collection of employee PII
Risk Level: HighVulnerable Code
javascript async function fetchEmployees() { const employees = new Map(); let pageToken = ''; try { do { const params = { department_id: '0', // Root department = all employees page_size: 50, user_id_type: 'user_id' }; if (pageToken) params.page_token = pageToken; const result = await larkApi('GET', '/contact/v3/users', { params }); for (const user of (result.items || [])) { employees.set(user.user_id, { user_id: user.user_id, name: user.name, en_name: user.en_name, nickname: user.nickname, email: user.email, mobile: user.mobile, department_ids: user.department_ids, open_id: user.open_id }); } pageToken = result.has_more ? result.page_token : ''; } while (pageToken);Technical Analysis
The declared employee-directory functionality only requires converting explicitly supplied names into Lark
user_idvalues. Instead of performing a targeted lookup, the implementation requests users from department0, paginates through the root directory, and stores every returned employee.It also retains sensitive or unnecessary fields, including email addresses, mobile numbers, department memberships, and Open IDs. These fields are not required for name-to-
user_idresolution. The collected records remain in a process-wide cache and can subsequently be returned by the exportedlistEmployees()andsearchEmployees()functions.This violates least-privilege and data-minimization principles. The behavior increases the sensitivity of the application process and broadens the impact of any code that can i ...[truncated 1138 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace tenant-wide enumeration with targeted lookups for only the names explicitly supplied by the user.
- Request and retain only
user_id,name,en_name, and, if essential,nickname. - Do not retain email addresses, mobile numbers, department memberships, or Open IDs.
- Remove or restrict the exported
listEmployees()andsearchEmployees()functions unless full-directory access is an explicit, authorized feature. - Use the narrowest Feishu contact scope that supports targeted lookup.
- Add explicit authorization checks before any directory-wide operation.
- Document the exact directory data accessed, its retention period, and its consumers.
- Clear cached directory records when they are no longer required and avoid returning mutable cached objects.
