T08 · Insecure Dependencies
- Location
video_downloader.py:29- Finding
Automatic Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
video_downloader.py:29-30
Vulnerability Type: Unpinned dependency installation from a mutable package source
Risk Level: MediumVulnerable Code
python subprocess.run([sys.executable, '-m', 'pip', 'install', '-U', 'yt-dlp'], check=True, capture_output=True)The installation is triggered automatically during ordinary download operations when the
yt-dlpexecutable cannot be found:python # 检查 yt-dlp if not check_yt_dlp(): print("⚠️ yt-dlp 未安装") if not install_yt_dlp(): return FalseTechnical Analysis
The script invokes pip with
install -U yt-dlpwithout specifying an exact version or verifying an expected package hash. As a result, the package artifact installed at runtime may change independently of the audited project. pip also honors environment-level package index configuration, so the package may be resolved through a configured index rather than a fixed, explicitly trusted repository.This creates a supply-chain risk: compromise of the package distribution channel, a configured package index, or a future upstream release could cause attacker-controlled code to be installed. Python packages can execute build or installation logic, and the installed
yt-dlpprogram is subsequently executed by the script.The use of an argument-list subprocess call prevents shell metacharacters from producing command injection, but it does not mitigate dependency provenance or integrity risks.
Attack Path
- An attacker compromises a package source used by pip, controls a configured package index, or causes a malicious future package artifact to be served.
- A user runs a normal video download while the
yt-dlpexecutable is unavailable. download_video()automatically callsinstall_yt_dlp().- The script runs
python -m pip install -U yt-dlpwithout a pinned version or package hash. - pip do ...[truncated 672 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from the normal download path. If the dependency is missing, stop and provide explicit setup instructions.
- Pin
yt-dlpto a reviewed exact version rather than using an unconstrained upgrade:text yt-dlp==REVIEWED_VERSION - Maintain a lock file containing cryptographic hashes and install with hash enforcement:
bash python -m pip install --require-hashes -r requirements.txt - Use a dedicated virtual environment with a trusted, explicitly configured package index.
- Separate installation from execution and require informed user confirmation before retrieving third-party software.
- Review and intentionally update the pinned dependency through a controlled maintenance process, including provenance and integrity checks.
