T08 · Insecure Dependencies
- Location
scripts/whisper_local.py:22- Finding
Automatic Execution of an Unpinned Third-Party Docker Image
- Content
View full analysis
Vulnerability Details
File Location:
scripts/whisper_local.py:22-23, 97-111
Additional Location:SKILL.md:44-54
Vulnerability Type: Unpinned mutable third-party dependency
Risk Level: MediumVulnerable Code
python CONTAINER_NAME = "whisper-asr" DOCKER_IMAGE = "onerahmet/openai-whisper-asr-webservice:latest"python # 容器不存在,创建新的 print(f"🆕 创建新容器 {self.CONTAINER_NAME} (模型: {self.model})...") cmd = [ "docker", "run", "-d", "-p", "9000:9000", "-e", f"ASR_MODEL={self.model}", "-e", "ASR_ENGINE=faster_whisper", "--name", self.CONTAINER_NAME, self.DOCKER_IMAGE ] result = subprocess.run(cmd, capture_output=True, text=True, timeout=120) if result.returncode == 0: return True else: print(f"❌ 创建容器失败: {result.stderr}") return FalseThe documentation also recommends executing the same mutable image:
bash docker run -d -p 9000:9000 --name whisper-asr onerahmet/openai-whisper-asr-webservice:latestTechnical Analysis
The Skill executes
onerahmet/openai-whisper-asr-webservice:latestwithout pinning the image to a reviewed cryptographic digest. Thelatesttag is mutable, meaning its contents can change after the Skill has been audited without requiring any modification to this repository.When the expected container does not already exist,
start_docker_container()invokesdocker run. Docker may retrieve the current image associated with the mutable tag and immediately execute it. Consequently, the effective runtime payload is controlled by the current state of an external container registry and upstream publisher.The documentation similarly recommends unversioned installation of
openai-whisperand execution of the samelatestimage. No signature verification, digest validation, software bill of materials, or explicit user confirmation is present.This finding does not establish that the current upstream image is malicious. The vulnerability is the absence of integrity ...[truncated 1705 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the container image to a reviewed immutable digest:
python DOCKER_IMAGE = ( "onerahmet/openai-whisper-asr-webservice" "@sha256:<reviewed-image-digest>" )-
Maintain an explicit dependency-update process that:
- Retrieves a candidate image.
- Verifies its signature and provenance.
- Scans it for known vulnerabilities.
- Reviews its software bill of materials.
- Updates the pinned digest only after approval.
-
Require explicit user approval before downloading or launching a previously unavailable image.
-
Pin Python dependencies to reviewed versions and hashes, for example through a locked requirements file using hash verification.
-
Harden the container with a non-root user, a read-only root filesystem, dropped Linux capabilities, resource limits, and restricted outbound networking where compatible with the service.
-
Document the exact reviewed image version and digest in
SKILL.mdrather than recommending the mutablelatesttag.
