T08 · Insecure Dependencies
- Location
requirements.txt:3- Finding
Unpinned Python Dependencies Installed Without Integrity Verification
- Content
View full analysis
=4.15.0; python_version >= '3.7' selenium>=3.141.0,<4.0.0; python_version < '3.7' ``` ```bash echo "Installing Python dependencies (--user, no sudo)..." python3 -m pip install --user -r "$SKILL_DIR/requirements.txt" ``` ### Technical Analysis The dependency specification permits mutable ranges rather than selecting exact, reviewed versions. The installation command also does not use package hashes or an option such as `--require-hashes`. Consequently, separate installations of the same Skill can retrieve different Selenium releases and transitive dependencies. Installation through `pip` may execute package build or installation logic under the account running setup. Although Selenium is a legitimate dependency required by the declared browser-automation functionality, the absence of version and artifact integrity controls unnecessarily expands the supply-chain attack surface. No evidence indicates that the current dependency name is malicious or typo-squatted. The issue is the lack of reproducible, authenticated dependency resolution. ### Attack Path 1. An attacker compromises an allowed upstream package release, package index, dependency artifact, or applicable network trust path. 2. A user runs `scripts/setup.sh`. 3. `pip` resolves the broad version constraint to the compromised release. 4. The malicious package or build logic executes with the privileges of the account running setup. 5. The package remains installed in the user's Python environment and can execute again when the publishing script imports Selenium. ### Impact Assessment Successful exploitation could execute arbitrary code as the user who runs setup, allowing access to that user's files and processes. In this project, that account may also have access ...[truncated 305 chars]- Remediation
View remediation
; python_version >= '3.7' selenium==3.141.0; python_version < '3.7' ``` 2. Generate and commit a lock file containing hashes for all direct and transitive dependencies. 3. Install with hash enforcement: ```bash python3 -m pip install --user --require-hashes -r requirements.lock ``` 4. Use a dedicated virtual environment rather than modifying the general user site-packages directory. 5. Regularly review pinned versions for security advisories and update them through a controlled process. 6. Continue prohibiting root installation in the normal setup workflow. ]]>
