T08 · Insecure Dependencies
- Location
pyproject.toml:6- Finding
Unbounded Authentication-Capable Third-Party Dependency
- Content
View full analysis
=3.0.5", ] ``` The installation instructions in `README.md:36-40` and `SKILL.md:14-18` direct users to resolve and install this dependency: ```bash uv sync ``` No reviewed lockfile is present in the audited project. ### Technical Analysis The version constraint only establishes a minimum version and permits the package resolver to install any later release satisfying `>=3.0.5`. Because no lockfile or integrity-pinned artifact is included, two installations at different times may receive different dependency code without any corresponding change to this project. This is security-sensitive because `scripts/lamp_cli.py` imports `mijiaAPI` and invokes its authentication and device-control interfaces. An eligible release compromised at the upstream repository, package registry, maintainer account, or build pipeline could therefore execute within the CLI process and interact with authentication state and smart-home operations. The audit did not establish that the current `mijiaapi` package is malicious. The finding concerns the project's unsafe dependency resolution policy and the absence of a reproducible, reviewed dependency set. ### Attack Path 1. An attacker compromises the package publisher, distribution account, release pipeline, or another eligible dependency release. 2. The attacker publishes a malicious version that satisfies `mijiaapi>=3.0.5`. 3. A user follows the documented installation process and runs `uv sync`. 4. The resolver selects and installs the malicious eligible version because no reviewed lockfile or exact integrity constraint prevents version drift. 5. The CLI imports the package and calls `mijiaAPI()` and `api.login()`. 6. Malicious dependency code executes with the privileges and environment of ...[truncated 671 chars]- Remediation
View remediation
