T08 · Insecure Dependencies
- Location
gongwen_template.js:7- Finding
Unpinned Third-Party npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
gongwen_template.js:7
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Lowjavascript /** * gongwen_template.js - 公文模板 for docx-js * * 基于 GB/T 9704-2012 和企业内部公文格式要求 * * 使用方法: * 1. npm install docx * 2. node gongwen_template.js */Technical Analysis
The usage instructions direct users to install the
docxpackage without specifying an exact version. The project also contains no reviewedpackage.jsonor committed lockfile that would constrain the package and its transitive dependencies to known versions.Running
npm install docxresolves mutable content from the configured npm registry. Package installation can execute npm lifecycle scripts unless scripts are explicitly disabled. Consequently, a future compromised package release, compromised transitive dependency, registry substitution, or malicious registry configuration could cause code not reviewed as part of this project to execute during installation.This finding concerns supply-chain integrity rather than confirmed malicious behavior in the current
docxpackage. The installation command is documentation and is not automatically executed by the Skill.Attack Path
- An attacker compromises a future release of
docx, one of its transitive dependencies, or the package registry used by the victim. - The attacker adds malicious code or an installation lifecycle script to the resolved package content.
- A user follows the documented
npm install docxcommand. - npm retrieves the mutable package version and dependency graph selected at installation time.
- Malicious package code or a lifecycle script executes with the privileges of the user running npm.
- Depending on those privileges, the payload could access files available to that user, alter project content, obtain environment variables, or establish network communication.
...[truncated 631 chars]
- An attacker compromises a future release of
- Remediation
View remediation
Remediation Suggestions
- Add a reviewed
package.jsonthat pinsdocxto an exact version rather than using a floating version range. - Generate, review, and commit a
package-lock.jsonso direct and transitive dependency versions and integrity hashes are reproducible. - Replace the documented installation workflow with
npm ci, which installs from the committed lockfile. - Use
npm ci --ignore-scriptswhen the selected dependency graph does not require lifecycle scripts. - Review dependency provenance, maintainers, release history, lifecycle scripts, and transitive dependencies before updating.
- Run dependency installation as an unprivileged user in an isolated development environment or container.
- Apply automated dependency and lockfile scanning, and require review for dependency updates.
- Add a reviewed
