T08 · Insecure Dependencies
- Location
INSTALL.md:14- Finding
Ambiguous and Unpinned Whisper Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
INSTALL.md:14andINSTALL.md:49
Vulnerability Type: Dependency confusion and unsafe package installation
Risk Level: MediumVulnerable Code
bash pip install whisper openai-whisper moviepy Pillow numpyThe guide later repeats the unnecessary package installation:
bash pip install whisper python -c "import whisper; whisper.load_model('base')"Technical Analysis
The project uses the module supplied by
openai-whisper, but the installation guide also tells users to install a separate package namedwhisper. Installing an ambiguous, unnecessary package by name increases dependency-confusion and package-substitution risk.The direct installation command also leaves all dependencies unpinned. Package content can therefore change between installations, and resolution depends on the package index configured in the user's environment. Python packages may execute build backend or installation logic during installation, so dependency installation is a code-execution boundary rather than a passive download.
The audit did not establish that the current
whisperpackage is malicious. The vulnerability is the unnecessary and ambiguous dependency instruction, combined with unrestricted package resolution.Attack Path
- A user follows the installation instructions and runs
pip install whisper. - Pip resolves the package from the user's configured public or private package index.
- An attacker who controls, substitutes, or shadows the resolved package supplies a malicious distribution.
- Pip executes the package's build or installation process, or the malicious package executes when imported.
- The payload runs with the privileges of the user performing the installation.
Impact Assessment
Successful exploitation can result in arbitrary code execution under the installing user's account. The payload could access files, environme ...[truncated 291 chars]
- A user follows the installation instructions and runs
- Remediation
View remediation
Remediation Suggestions
-
Remove every instruction that installs the separate
whisperpackage. -
Document only the package actually required by the code:
bash python -m pip install openai-whisper -
Pin all production dependencies to reviewed versions instead of using unrestricted lower bounds.
-
Generate a lock file with cryptographic hashes and require hash verification during installation, such as
pip install --require-hashes. -
Use an approved package index and explicitly configure trusted internal mirrors where applicable.
-
Run dependency installation in an isolated virtual environment without administrator privileges.
-
Add automated software-composition analysis and periodic dependency review to detect compromised or vulnerable releases.
-
