T08 · Insecure Dependencies
- Location
SKILL.md:52- Finding
Unpinned Third-Party Installer Creates Supply-Chain Exposure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:52-58
Mirrored Locations:README.md:63-68,README-CN.md:63-68
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumComplete Code Snippet:
bash # 5. Install OpenMMLab packages python -m pip install --upgrade pip python -m pip install setuptools==81.0.0 wheel python -m pip install -U openmim mim install mmengine==0.10.1 mim install mmcv==2.1.0 python -m pip install mmsegmentation==1.2.2 mmdet==3.3.0 mmpretrain==1.2.0Technical Analysis
The instructions install or upgrade
openmimwithout specifying an exact version or verifying an integrity hash:bash python -m pip install -U openmimConsequently, the package selected at installation time can differ from the package that existed when the Skill was reviewed. Python package installation can execute package build hooks and other installation logic with the privileges of the invoking user.
The subsequently invoked
mimexecutable is trusted to resolve and install additional packages. Although several downstream package versions are pinned, their artifacts are not protected by hashes, and the source index is not explicitly constrained.No evidence indicates that
openmimor the named packages are currently malicious. The issue is the absence of controls that make third-party dependency retrieval reproducible and resistant to repository compromise, package takeover, or unexpected upstream changes.Attack Path
- An upstream package release, package repository, maintainer account, or dependency is compromised.
- The user follows the Skill and runs
python -m pip install -U openmim. - Pip retrieves the latest package accepted by its resolver rather than a reviewed, immutable artifact.
- Malicious installation or build logic executes under the invoking user's account.
- The installed
mimcommand can then run or retrieve ...[truncated 870 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin
openmimto a specifically reviewed version rather than using-U:bash python -m pip install openmim==<reviewed-version> -
Publish a hash-locked requirements file and install with hash verification:
bash python -m pip install --require-hashes -r requirements.lock -
Pin all direct and transitive dependencies to tested versions.
-
Explicitly use an approved package index and disable unintended extra indexes.
-
Verify downloaded wheel hashes or package signatures before installation.
-
Run dependency installation in a disposable, non-privileged environment.
-
Document the date, source, and hashes of the dependency set described as “verified.”
-
Avoid running package installation commands with
sudoor from an administrative shell.
-
