T08 · Insecure Dependencies
- Location
setup.md:14- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
setup.md, lines 14–17
Vulnerability Type: Unpinned dependency installed from the active Python package index
Risk Level: MediumVulnerable Code:
markdown ### Option 1: pip ```bash pip3 install speedtest-clitext The same unpinned installation command is repeated as troubleshooting guidance at `setup.md`, lines 41–44. ### Technical Analysis The setup documentation instructs users to install `speedtest-cli` without specifying an exact reviewed version or validating package hashes. Although the requirements table states that version 2.x is expected, the installation command does not enforce that constraint and may resolve any version offered by the configured package index. Python package installation can execute package-controlled build or installation logic. Consequently, compromise of the package publisher, package index, dependency resolution path, or local pip index configuration could cause attacker-controlled code to execute during installation. The absence of hash verification also prevents pip from detecting an artifact that differs from the reviewed release. This is a supply-chain weakness rather than evidence that the currently named package is malicious. ### Attack Path 1. An attacker compromises the package publisher, distribution account, configured package index, or network/dependency resolution environment. 2. The attacker makes a malicious or substituted `speedtest-cli` distribution available through the index used by pip. 3. A user follows the documented `pip3 install speedtest-cli` instruction. 4. Pip resolves and downloads the unpinned artifact without checking a project-supplied cryptographic hash. 5. Attacker-controlled installation or build logic executes with the privileges of the user running pip. 6. The installed executable may subsequently execute additional attacker-controlled behavior whenever the skill invokes `speedtes ...[truncated 519 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin
speedtest-clito an exact, reviewed version rather than accepting any available release. -
Record cryptographic hashes in a locked requirements file, for example:
text speedtest-cli==REVIEWED_VERSION \ --hash=sha256:REVIEWED_DISTRIBUTION_HASH -
Install using hash enforcement:
bash python3 -m pip install --require-hashes -r requirements.txt -
Review and update the pinned version and hashes through a controlled dependency-update process.
-
Recommend installation in an isolated virtual environment under an unprivileged account.
-
Specify the trusted package index explicitly where appropriate and avoid unreviewed additional indexes.
-
Update the troubleshooting section so it does not reintroduce the unpinned installation command.
-
