T08 · Insecure Dependencies
- Location
scripts/bot.py:9- Finding
Automatic Runtime Installation of an Unpinned Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/bot.py:9-16
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: HighVulnerable Code:
python # Try to import telegram, install if needed try: from telegram import Update from telegram.ext import Application, CommandHandler, MessageHandler, filters, ContextTypes except ImportError: print("Installing python-telegram-bot...") os.system("pip install python-telegram-bot") from telegram import Update from telegram.ext import Application, CommandHandler, MessageHandler, filters, ContextTypesTechnical Analysis
The script automatically invokes
pipwhen the Telegram dependency cannot be imported. The package has no exact version constraint, integrity hash, lockfile, trusted artifact restriction, or user confirmation. Consequently, the code installed depends on whatever package release and transitive dependencies the package index supplies at execution time.Although the command itself is constant and does not create a direct shell-injection issue, this design creates a supply-chain exposure. Installation may run package build or installation logic, and the subsequent import executes the installed package's module-level code. It also modifies the active Python environment without an explicit setup operation.
Attack Path
- The bot is started in an environment where
python-telegram-botis unavailable or fails to import. - The
ImportErrorhandler automatically invokespip install python-telegram-bot. - Pip resolves the latest available package and its transitive dependencies without checking project-pinned versions or expected hashes.
- A compromised, malicious, or unexpectedly changed upstream artifact is downloaded and installed.
- Installation logic or the imports immediately following installation execute attacker-controlled code.
- The code runs with the same operating-system ...[truncated 590 chars]
- The bot is started in an environment where
- Remediation
View remediation
Remediation Suggestions
- Remove all runtime package installation from the application.
- Declare
python-telegram-botand its reviewed version in a dependency manifest or lockfile. - Pin exact versions and verify downloaded artifacts with cryptographic hashes, such as through
pip --require-hashes. - Install dependencies during a separate, explicit deployment or build phase inside an isolated virtual environment or container.
- Use an approved internal package mirror where appropriate and continuously scan direct and transitive dependencies.
- If the dependency is missing at runtime, terminate with a clear error rather than modifying the environment automatically.
- Avoid
os.system()for process execution. Where a fixed administrative subprocess is genuinely necessary, usesubprocess.run()with an argument list, explicit interpreter selection, and failure checking.
