T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unbounded Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1
Additional Locations:SKILL.md:98,SKILL.md:139
Vulnerability Type: Unpinned dependency and transitive supply-chain exposure
Risk Level: MediumComplete Code Snippet:
text gql[websockets]>=3.4.0The installation instructions also resolve the dependency without a lock file or integrity hashes:
bash pip install 'gql[websockets]'Technical Analysis
The project permits any available version of
gqlequal to or newer than 3.4.0 and does not lock or hash its transitive WebSocket dependencies. Consequently, the code that users install can differ from the dependency set represented at audit time.Python packages may execute code during installation and whenever imported. If a future permitted release or one of its transitive dependencies is compromised, the malicious package would execute with the privileges of the user installing or running the skill. The process also has access to
BITQUERY_API_KEY, making that credential available to compromised dependency code.No evidence was found that the currently named package is malicious. The vulnerability is the unconstrained and unverifiable dependency resolution process.
Attack Path
- An attacker compromises the publishing account, build pipeline, or distribution channel of a permitted dependency or transitive dependency.
- The attacker publishes a malicious release whose version satisfies
gql[websockets]>=3.4.0. - A user follows the documented installation command without a reviewed lock file or required hashes.
pipresolves and installs the malicious permitted release.- Malicious installation or import-time code executes with the user's privileges.
- The code can read process-accessible files and environment variables, including
BITQUERY_API_KEY, and transmit them externally.
Impact Assessment
Successful exploitation provides code e ...[truncated 340 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
gqland every transitive dependency to versions that have been reviewed and tested. - Generate and commit a reproducible lock file using a tool such as
pip-tools, Poetry, or an equivalent dependency manager. - Record package hashes and install with
pip install --require-hashesso altered distributions are rejected. - Use an internal package mirror or allowlist where appropriate.
- Run dependency vulnerability and provenance checks in CI.
- Install dependencies in a dedicated virtual environment or container under a non-privileged account.
- Establish a controlled process for reviewing and updating pinned versions.
- Pin
