T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Dependencies Allow Supply-Chain Substitution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:31; related installation guidance inreferences/notes.md:23-24andscripts/extract.py:135-136
Vulnerability Type: Unpinned Python package installation
Risk Level: MediumVulnerable Code
bash pip install pdfplumberRelated fallback instructions:
markdown - **pdfplumber** — primary PDF extraction: `pip install pdfplumber` - **PyPDF2** — fallback if pdfplumber unavailable: `pip install PyPDF2`The executable also prints the same unpinned installation commands:
python print(" pip install pdfplumber", file=sys.stderr) print(" # or: pip install PyPDF2", file=sys.stderr)Technical Analysis
The installation instructions request packages by name without specifying an audited version or validating package hashes. Consequently, the code installed by a user depends on whichever release the package index serves at installation time rather than the release reviewed with this project.
This is a supply-chain weakness rather than evidence that the current
pdfplumberorPyPDF2packages are malicious. Exploitation would require compromise of an upstream package, maintainer account, package-distribution channel, or resolution environment. A compromised distribution can execute code during installation through build hooks or later when imported byscripts/extract.py.Attack Path
- An attacker compromises an upstream dependency release, maintainer account, package index, or package-resolution environment.
- The victim follows the documented
pip install pdfplumberor fallbackpip install PyPDF2instruction. - Because no version or cryptographic hash is enforced, pip retrieves the attacker-controlled release.
- Malicious code executes during package build or installation, or when
extract_pdf_text()imports the package. - The payload operates with the permissions of the user or service running pip and the in ...[truncated 510 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each supported dependency to a reviewed version, for example through a committed requirements file:
text pdfplumber==<reviewed-version> PyPDF2==<reviewed-version> - Generate and enforce cryptographic hashes:
bash python3 -m pip install --require-hashes -r requirements.txt - Pin transitive dependencies using a lock-file workflow such as
pip-tools, Poetry, or uv. - Replace every installation example and runtime error message with the locked installation command.
- Run dependency vulnerability and provenance checks in CI, and review automated dependency updates before merging.
- Install into an isolated virtual environment under an unprivileged account; do not recommend
sudo pip. - Prefer a trusted, explicitly configured package index and retain verified dependency artifacts where reproducible deployment is required.
- Pin each supported dependency to a reviewed version, for example through a committed requirements file:
