T08 · Insecure Dependencies
- Location
README.md:16- Finding
Unpinned Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
README.md:16-20
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code:
bash ## Installation Dependencies ```bash pip install pdfplumber PyYAMLtext ### Technical Analysis The documented installation command retrieves mutable package versions from the user's configured Python package index. Neither dependency is constrained to a reviewed version, and the project provides no lock file or cryptographic hashes for artifact verification. As a result, the code installed by users can differ from the code that was reviewed during this audit. If a dependency publisher account, package repository, package release, or local package-index configuration is compromised, an attacker-controlled distribution could be selected during dependency resolution. Python packages may execute code during installation or when imported by `scripts/deep_reader.py`. This finding concerns supply-chain integrity. The audit found no evidence that `pdfplumber` or `PyYAML` is currently malicious. ### Attack Path 1. An attacker compromises a dependency publisher account, package repository, upstream release process, or package index used by the victim. 2. The attacker publishes or serves a malicious version of `pdfplumber`, `PyYAML`, or one of their transitive dependencies. 3. A user follows the project documentation and runs `pip install pdfplumber PyYAML`. 4. Pip resolves and downloads the attacker-controlled artifact because no reviewed versions or hashes are enforced. 5. Malicious code executes during package installation or when the dependency is imported and used. 6. The payload runs with the permissions of the user performing the installation or invoking the skill. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to files readable ...[truncated 426 chars]- Remediation
View remediation
Remediation Suggestions
- Create a dependency file that pins every direct and transitive dependency to a reviewed version.
- Generate and record SHA-256 hashes for all approved distributions.
- Require hash verification during installation:
bash python -m pip install --require-hashes -r requirements.txt - Use a lock-file generation tool such as
pip-toolsand review dependency changes before updating the lock file. - Prefer an approved package index and explicitly configure trusted repository sources in controlled environments.
- Run dependency vulnerability and provenance checks in CI.
- Install dependencies inside an isolated virtual environment without administrative privileges.
