T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Playwright Dependency Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9–10
Vulnerability Type: Unpinned third-party dependency and remotely retrieved browser component
Risk Level: MediumComplete Code Snippet
markdown - `npm install playwright` - `npx playwright install chromium`Technical Analysis
The setup instructions install Playwright without specifying an audited version or enforcing a lockfile. Consequently,
npm install playwrightresolves whatever package version and transitive dependency graph the configured npm registry serves at installation time.The subsequent
npx playwright install chromiumcommand executes the installed Playwright CLI and downloads a Chromium artifact. Neither an expected version nor an integrity-verification procedure is documented. The effective components can therefore change after the skill has been reviewed.This is a supply-chain weakness rather than evidence that the current Playwright package is malicious. Exploitation requires compromise or manipulation of a package release, transitive dependency, registry response, local npm configuration, or browser distribution artifact.
Attack Path
- An attacker compromises a relevant Playwright release, transitive dependency, npm distribution path, configured registry, or Chromium artifact source.
- A user follows the documented setup instructions.
npm install playwrightresolves and installs mutable third-party code without a project-enforced version or lockfile.npx playwright install chromiumexecutes the installed CLI and retrieves an external browser artifact.- Compromised installation code, lifecycle behavior, CLI code, or browser content executes under the installing user's account.
Impact Assessment
Successful exploitation could provide code execution with the privileges of the user performing installation. The resulting access could include project files and other files readable or writable by that account, environment vari ...[truncated 352 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Playwright to a reviewed exact version rather than resolving the latest release:
bash npm install --save-exact playwright@<reviewed-version> - Commit the generated lockfile and use
npm ciso installations reproduce the reviewed dependency graph. - Enforce lockfile integrity in CI and reject unexpected lockfile modifications.
- Configure an approved npm registry and consider an internal dependency proxy that scans and retains reviewed artifacts.
- Pin the associated browser revision through the selected Playwright release and document the expected download source.
- Verify downloaded browser artifacts through trusted checksums or signatures where the distribution process supports them.
- Perform dependency and provenance checks before upgrades, and test upgrades in an isolated environment.
- Run installation with a minimally privileged account or disposable container, without unrelated credentials or sensitive host mounts.
- Avoid permitting untrusted project-level or user-level npm configuration to redirect package or browser downloads.
- Pin Playwright to a reviewed exact version rather than resolving the latest release:
