T08 · Insecure Dependencies
- Location
README.md:24- Finding
Unpinned and Unverified pyTigerGraph Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md:24
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash pip install pyTigerGraphTechnical Analysis
The installation command retrieves the latest available
pyTigerGraphrelease without enforcing an exact version, package hash, or trusted lock file. Consequently, the installed code can change over time without any corresponding change to this project.The package name appears legitimate, and the audit found no evidence that the project currently retrieves a known malicious dependency. Nevertheless, this installation pattern leaves users exposed if the package registry, publisher account, release process, or dependency graph is compromised. Python packages may execute code during build or installation, and subsequently execute package-controlled code when imported.
Attack Path
- An attacker compromises the upstream package publisher, registry entry, release pipeline, or a transitive dependency.
- The attacker publishes a malicious release under the expected package name.
- A user follows the documented
pip install pyTigerGraphcommand. pipresolves the unpinned dependency to the attacker-controlled release.- Malicious code executes during package installation, wheel build, or later import by an application.
- The payload obtains the permissions of the user or service account running
pipor the consuming application.
This path requires an external supply-chain compromise or malicious upstream release; no such compromise was confirmed during this audit.
Impact Assessment
Successful exploitation could permit arbitrary Python code execution with the privileges of the installing user. If installation is performed as root, within a privileged CI runner, or in a production service image, the impact may include host or build-environment compromise, theft of environment ...[truncated 353 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
pyTigerGraphto a reviewed, exact version, for example through a version-controlled requirements file. - Generate and verify cryptographic hashes using a tool such as
pip-compile --generate-hashes, then install withpip install --require-hashes -r requirements.txt. - Prefer binary wheels where appropriate and disable unnecessary source builds in controlled deployment environments.
- Use a trusted internal package mirror or allowlisted index for production and CI installations.
- Scan direct and transitive dependencies with an automated vulnerability and provenance checking process.
- Run package installation as an unprivileged user in an isolated virtual environment or build container.
- Review and intentionally approve dependency upgrades rather than resolving the newest release during every installation.
- Pin
