T08 · Insecure Dependencies
- Location
qimen-dunjia.html:8- Finding
Unpinned Third-Party Scripts Execute Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
qimen-dunjia.html, lines 8–13
Vulnerability Type: Mutable remote dependencies without Subresource Integrity
Risk Level: MediumVulnerable Code
html <!-- Core dependencies --> <script src="https://unpkg.com/react@18/umd/react.production.min.js"></script> <script src="https://unpkg.com/react-dom@18/umd/react-dom.production.min.js"></script> <script src="https://unpkg.com/@babel/standalone/babel.min.js"></script> <script src="https://cdn.tailwindcss.com"></script> <!-- Icon library --> <script src="https://unpkg.com/lucide@latest"></script>Technical Analysis
When the HTML interface is opened, the browser downloads and executes JavaScript from
unpkg.comandcdn.tailwindcss.com. None of these resources has a Subresource Integrity hash. Several URLs also use mutable version selectors, including@18, an unversioned package reference, and@latest.Consequently, the code ultimately executed is not fully represented by the audited project. It may change when an upstream package release, CDN response, or package tag changes. HTTPS protects data in transit but does not ensure that future content at the same URL remains identical to the audited content.
This creates a third-party supply-chain exposure. Compromise of a referenced package, package publisher account, CDN, or mutable release could cause attacker-controlled JavaScript to execute in the page context.
Attack Path
- An attacker compromises a referenced package release, publisher account, CDN delivery path, or mutable package tag.
- The attacker causes one of the referenced URLs to serve modified JavaScript.
- A user opens
qimen-dunjia.htmlwhile connected to the network. - The browser retrieves the modified dependency because the page neither pins immutable reviewed artifacts nor verifies integrity.
- The malicious script executes with the privileges of JavaScript in the page context.
- It can alter displayed results, ...[truncated 835 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace floating dependency references such as
@18and@latestwith exact, reviewed versions. - Prefer vendoring the reviewed production builds inside the project and serving them locally.
- If CDN hosting remains necessary, add valid Subresource Integrity hashes and
crossorigin="anonymous"to every external script that supports immutable assets. - Avoid runtime Babel and the Tailwind CDN production helper. Precompile JSX and CSS during a controlled build process, then ship static generated assets.
- Introduce a restrictive Content Security Policy. Limit
script-srcto approved immutable sources and avoid allowances such asunsafe-evalwhere practical. - Add dependency update review, lockfile verification, provenance checks, and automated vulnerability scanning to the release process.
- Recalculate and review integrity hashes whenever an intentionally pinned dependency is upgraded.
- Replace floating dependency references such as
