T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Allow Unreviewed Package Updates
- Content
View full analysis
=1.0.0 numpy>=1.20.0 ``` `README.md:21`: ```bash pip install xtquant ``` `demo_project/README.md:9`: ```bash pip install -r ../requirements.txt ``` ### Technical Analysis The project permits any current or future version of `xtquant` and `numpy` above the stated minimum versions. The direct installation command for `xtquant` has no version constraint at all. No lock file, package hashes, trusted package index, or integrity-verification procedure is provided. Consequently, dependency resolution can install package releases that were not reviewed when this project was audited. Python packages can execute code during installation in some distribution workflows and can always execute package-level code when imported. The demonstration imports `xtquant` at `demo_project/demo.py:6`, making a compromised installed release reachable during normal use. This finding does not establish that the named packages are currently malicious. It identifies a supply-chain weakness through which a compromised future release, package-index compromise, or unsafe index configuration could introduce executable code into the trading environment. ### Attack Path 1. An attacker compromises a permitted dependency release or the package source used by the victim. 2. The attacker publishes a version satisfying `xtquant>=1.0.0` or `numpy>=1.20.0`. 3. A user follows the documented `pip install` instructions without a reviewed lock file or hash verification. 4. The package manager resolves and installs the attacker-controlled release. 5. Malicious code executes during installation or when the package is imported. 6. The code runs with ...[truncated 875 chars]- Remediation
View remediation
