T08 · Insecure Dependencies
- Location
scripts/clonev.sh:34- Finding
Mutable Remote Container Image Is Executed with Access to Host Data
- Content
View full analysis
&2 ``` ### Technical Analysis The script executes `ghcr.io/coqui-ai/tts:latest`, which is identified only by a mutable tag. A mutable tag can resolve to different container contents in future executions without any change to this reviewed project. There is no immutable digest, signature verification, provenance check, or version lock. The container receives writable host mounts for the model cache, all retained voice samples, and generated output. Consequently, code in the image can read every voice recording in the shared sample directory and modify files in all three mounted host directories. The container is also not configured with network isolation, a read-only root filesystem, dropped capabilities, or an explicit non-root user. This is a supply-chain exposure. The reviewed repository does not itself prove that the current upstream image is malicious, but its effective executable payload can change after review. ### Attack Path 1. An attacker compromises the upstream image publisher, registry account, build pipeline, or mutable `latest` tag. 2. The `latest` tag is changed to reference an altered image. 3. A user invokes `scripts/clonev.sh`. 4. Docker retrieves or runs the altered image. 5. The altered image reads voice recordings from `/samples` and can modify the writable model and output mounts. 6. If outbound networking ...[truncated 677 chars]- Remediation
View remediation
" ``` 2. Verify image provenance and signatures before deployment, and update the digest only through a controlled review process. 3. Mount the model directory read-only when runtime modification is unnecessary: ```bash -v "${COQUI_DIR}/models-xtts:/root/.local/share/tts:ro" ``` 4. Expose only the selected voice sample through a private per-run directory rather than mounting the shared sample collection. 5. Use a separate, permission-restricted output directory for each invocation. 6. Disable networking when it is not required: ```bash --network none ``` 7. Harden the container with an explicit non-root user, dropped Linux capabilities, `no-new-privileges`, resource limits, and a read-only root filesystem where compatible. ]]>
