T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/relaunch_wechat_open_moments.py:36- Finding
Full-Desktop Screenshots Persist in a Predictable Temporary Directory
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/relaunch_wechat_open_moments.py:16-28,36scripts/publish_with_caption_verify.py:18-28,123scripts/click_publish_ocr.py:17-25,59
Vulnerability Type: Excessive desktop capture and persistent storage of potentially sensitive screen content
Risk Level: MediumComplete Vulnerable Code Snippets:
scripts/relaunch_wechat_open_moments.py:16-28,34-38python TMP_DIR = Path( os.environ.get( "WECHAT_MOMENTS_TMP", str(Path(tempfile.gettempdir()) / "wechat_moments"), ) ) TMP_DIR.mkdir(parents=True, exist_ok=True) SHOT = TMP_DIR / "relaunch_wechat_open_moments.png" DEFAULT_WECHAT_EXE = r"C:\Program Files\Tencent\Weixin\Weixin.exe" WECHAT_EXE = os.environ.get("WECHAT_EXE", DEFAULT_WECHAT_EXE) def grab_ocr(): ImageGrab.grab().save(str(SHOT)) res, _ = engine(str(SHOT)) return res or []scripts/publish_with_caption_verify.py:18-28,123python TMP_DIR = Path( os.environ.get( "WECHAT_MOMENTS_TMP", str(Path(tempfile.gettempdir()) / "wechat_moments"), ) ) TMP_DIR.mkdir(parents=True, exist_ok=True) crop_path = TMP_DIR / "compose_crop_now.png" custom_keywords = [ kw.strip() for kw in os.environ.get("WECHAT_MOMENTS_VERIFY", "").split(",") if kw.strip() ] ImageGrab.grab().save(str(TMP_DIR / "after_publish_attempt.png"))scripts/click_publish_ocr.py:17-25,59python TMP_DIR = Path( os.environ.get( "WECHAT_MOMENTS_TMP", str(Path(tempfile.gettempdir()) / "wechat_moments"), ) ) TMP_DIR.mkdir(parents=True, exist_ok=True) ImageGrab.grab().save(str(TMP_DIR / "after_publish_click.png"))Technical Analysis
ImageGrab.grab()without abboxargument captures the entire desktop rather than only the WeChat Moments window required by the automation. This can include content from un ...[truncated 1965 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace every unrestricted
ImageGrab.grab()call with a capture limited to the validated WeChat or Moments window:python screenshot = ImageGrab.grab( bbox=(w.left, w.top, w.left + w.width, w.top + w.height) ) -
Avoid retaining OCR screenshots. Process captures in memory where supported, or delete temporary images immediately in a
finallyblock:python try: screenshot.save(str(path)) result, _ = engine(str(path)) finally: path.unlink(missing_ok=True) -
Make diagnostic screenshot retention explicitly opt-in and disabled by default.
-
Use a unique per-run directory created through secure temporary-file APIs instead of fixed filenames in a shared predictable directory.
-
Apply access controls that limit screenshot access to the current user where the operating system and deployment model permit it.
-
Add startup and shutdown cleanup for stale screenshots left by interrupted executions.
-
Document that diagnostic images may contain sensitive information if an operator deliberately enables retention.
-
