T08 · Insecure Dependencies
- Location
scripts/axe-mcp.js:13- Finding
Mutable Docker Image Is Executed Without Digest Pinning
- Content
View full analysis
Vulnerability Details
File Location:
scripts/axe-mcp.js:13, 31-38;SKILL.md:12-16
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: MediumVulnerable Code
scripts/axe-mcp.js:13:js const DOCKER_IMAGE = "dequesystems/axe-mcp-server:latest";scripts/axe-mcp.js:31-38:js const dockerArgs = [ "run", "-i", "--rm", "-e", `AXE_API_KEY=${AXE_API_KEY}`, ]; if (process.env.AXE_SERVER_URL) { dockerArgs.push("-e", `AXE_SERVER_URL=${process.env.AXE_SERVER_URL}`); } dockerArgs.push(DOCKER_IMAGE);SKILL.md:12-16:markdown ## Prerequisites - Docker running locally - `AXE_API_KEY` environment variable set - Docker image pulled: `dequesystems/axe-mcp-server:latest`Technical Analysis
The wrapper executes
dequesystems/axe-mcp-server:latest, which is a mutable image reference. The image content associated with thelatesttag can be replaced after the Skill has been audited. Consequently, the code that ultimately runs is not cryptographically bound to a reviewed artifact.Although the image is obtained from the documented vendor namespace, relying on a mutable tag leaves execution dependent on the ongoing security of the upstream publisher account, registry, and release process. A compromised publisher account, registry compromise, or unsafe future image release could silently change the effective executable payload.
Attack Path
- An attacker compromises the upstream image publication process or gains the ability to replace the image associated with the
latesttag. - The attacker publishes a modified image under
dequesystems/axe-mcp-server:latest. - A user pulls the updated image or runs the wrapper on a system configured to obtain the current tag.
- The wrapper starts the attacker-controlled image through Docker.
- The malicious container receives
AXE_API_KEY, the optional `AXE_S ...[truncated 942 chars]
- An attacker compromises the upstream image publication process or gains the ability to replace the image associated with the
- Remediation
View remediation
Remediation Suggestions
-
Pin the Docker image to a reviewed immutable digest:
js const DOCKER_IMAGE = "dequesystems/axe-mcp-server@sha256:<reviewed-image-digest>"; -
Verify the digest against an authenticated vendor release channel before adoption.
-
Establish a controlled update process in which new image digests are scanned, tested, reviewed, and explicitly committed.
-
Use signature verification, such as Sigstore/Cosign, if supported by the image publisher.
-
Add automated policy checks that reject mutable tags such as
latestin executable container references. -
Apply additional container restrictions where compatible, including a read-only filesystem, dropped Linux capabilities,
no-new-privileges, resource limits, and constrained network access.
-
