T08 · Insecure Dependencies
- Location
scripts/setup_local_demo_env.sh:21- Finding
Unpinned Third-Party Dependencies Allow Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup_local_demo_env.sh:21-22
Additional Location:references/local-webcam-demo.md:41-42
Vulnerability Type: Unpinned and integrity-unverified package installation
Risk Level: MediumVulnerable Code:
bash python -m pip install --upgrade pip setuptools wheel python -m pip install numpy opencv-python pillow ai-edge-litertTechnical Analysis
The setup script installs the latest available versions of several packages and their transitive dependencies from the configured Python package index. It does not use exact version constraints, a lockfile, package hashes, or repository restrictions.
Python package installation can execute package build-system code. Installed packages also execute code when imported by the webcam application. Consequently, a compromised package release, compromised transitive dependency, dependency-confusion condition in a custom package-index configuration, or future malicious update could execute code under the account running the setup script.
Upgrading
pip,setuptools, andwheelwithout pinning also changes the build toolchain during installation, making the environment difficult to reproduce or audit.Attack Path
- An attacker compromises one of the named packages, one of its transitive dependencies, or a package index used by the victim.
- The attacker publishes a malicious version that satisfies the unconstrained dependency request.
- The user follows the documented setup process and runs
scripts/setup_local_demo_env.sh. pipresolves and installs the attacker-controlled release.- Malicious build hooks execute during installation, or malicious runtime code executes when the webcam script imports the installed package.
Impact Assessment
Malicious package code would execute with the privileges of the user running the setup command. It could access files, environment variables, came ...[truncated 207 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version in a requirements file.
- Generate a complete lockfile that also pins transitive dependencies.
- Record and enforce package hashes, for example:
bash python -m pip install --require-hashes -r requirements.lock - Pin packaging tools instead of upgrading them to unrestricted latest versions.
- Explicitly configure the trusted package index and disable unintended extra indexes.
- Add automated dependency vulnerability and provenance scanning.
- Update
references/local-webcam-demo.mdto use the same locked installation procedure.
