T08 · Insecure Dependencies
- Location
scripts/install_dep.sh:27- Finding
Remote executable packages are installed without explicit integrity verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_dep.sh:27-31, 57-58
Vulnerability Type: Supply-chain integrity weakness
Risk Level: HighVulnerable Code
bash curl -fSL -o "$TMP_DIR/$QB_DEB" "${BASE_URL}/${QB_DEB}" dpkg -i "$TMP_DIR/$QB_DEB" || apt-get install -f -ybash curl -fSL -o "$TMP_DIR/$QB_RPM" "${BASE_URL}/${QB_RPM}" yum install -y "$TMP_DIR/$QB_RPM"bash curl -fSL -o "$TMP_DIR/$X5USE_WHL" "${BASE_URL}/${X5USE_WHL}" pip3 install --break-system-packages --ignore-installed "$TMP_DIR/$X5USE_WHL"Technical Analysis
The installation script downloads native browser packages and a Python wheel from an external HTTPS server and immediately installs them. Although HTTPS protects the transfer in transit, the script does not verify pinned cryptographic hashes, a signed manifest, or an explicitly trusted package signature before installation.
Package installation is a code-execution boundary. Native package installation can execute package-maintainer scripts, while Python package installation may execute build or installation logic. The use of
--break-system-packagesand--ignore-installedalso permits the wheel to modify the system Python environment and replace existing packages rather than remaining isolated.The artifact filenames are versioned, which improves reproducibility, but filenames alone do not establish integrity. This finding does not prove that the current hosted packages are malicious; it establishes that compromise or unauthorized replacement of those packages would not be detected by this script.
Attack Path
- An attacker compromises the external distribution account, server, publication pipeline, or hosted artifact.
- The attacker replaces one of the expected
.deb,.rpm, or.whlfiles while retaining its expected filename. - A user runs the documented
scripts/install_dep.shcommand. curldownloads the substituted artifact successfully over HTTPS.- Because no p ...[truncated 777 chars]
- Remediation
View remediation
Remediation Suggestions
- Publish a SHA-256 or stronger digest for every downloaded artifact in a trusted, version-controlled file distributed with the Skill.
- Verify each artifact before invoking
dpkg,yum, orpip3, and terminate installation on any mismatch. - Prefer vendor-signed package repositories and ensure package-manager signature verification remains enabled.
- For directly distributed artifacts, verify detached signatures against a pinned vendor public key.
- Pin immutable artifact versions and avoid mutable download paths.
- Install the Python wheel in a dedicated virtual environment rather than using
--break-system-packages. - Remove
--ignore-installedunless replacement of installed packages is explicitly required and reviewed. - Generate and retain a dependency inventory or software bill of materials for the browser package and wheel.
- Run installation with the minimum privileges required and separate package acquisition from privileged installation.
