T08 · Insecure Dependencies
- Location
README.md:5- Finding
Unpinned npm Package Execution Through a Mutable Release Tag
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 5–7
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumbash npx clawhub@latest install expense-trackerTechnical Analysis
The documented installation command uses
npxto download and execute the npm package identified by the mutablelatesttag. The project does not pin an exact package version or provide an integrity hash, lockfile, vendored installer, or package-verification procedure.As a result, the effective installer code can change after this project has been audited. Anyone who compromises the upstream package, its maintainer account, or its publishing workflow could cause subsequent installations to execute attacker-controlled code. The reviewed project contains only documentation and metadata, so the behavior of the externally obtained installer cannot be verified from the local artifact.
Attack Path
- An attacker compromises the npm package, a maintainer account, or the upstream release pipeline for
clawhub. - The attacker publishes a malicious version and assigns or causes it to receive the
latestdistribution tag. - A user follows the installation command in
README.md. npxresolvesclawhub@latest, downloads the attacker-controlled release, and executes its CLI or applicable lifecycle code.- The malicious process operates with the privileges and environment of the invoking user.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the invoking user's privileges. Depending on that user's access and the malicious package behavior, the compromise could affect local files, environment variables, developer credentials, application configuration, and other resources accessible to the user. The issue does not independently demonstrate privilege escalation; its scope is limited to the permissions already held by the process running
npx.- An attacker compromises the npm package, a maintainer account, or the upstream release pipeline for
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latesttag with an exact, reviewed package version. - Verify the downloaded package against a trusted integrity digest or signed provenance before execution.
- Document the authoritative package registry and publisher identity.
- Use a lockfile or similarly reproducible dependency mechanism where applicable.
- Prefer a locally included and auditable installer rather than downloading executable installer logic at runtime.
- Establish an update process in which new installer versions are reviewed and their integrity values are updated explicitly.
- Avoid running the installation command with elevated privileges.
- Replace the mutable
