T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned VCS Dependency Installation from a Mutable Branch
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-26;README.md:54-56
Vulnerability Type: Supply-chain exposure through an unpinned VCS installation source
Risk Level: MediumVulnerable Code
SKILL.md:24-26:bash pip install git+https://github.com/minirr890112-byte/popular-web-designs.gitREADME.md:54-56:bash # As a pip package pip install git+https://github.com/minirr890112-byte/popular-web-designs.gitTechnical Analysis
The documented installation command retrieves the package from the repository's current default branch without specifying an immutable release tag or full commit SHA. Consequently, the code installed by users can change after the audited version has been reviewed.
Python package installation can execute package build logic. If the upstream repository or maintainer account is compromised, an attacker could modify package source code or build configuration on the default branch. Users who subsequently follow the documented command would retrieve and install that modified version.
This is a supply-chain integrity issue rather than evidence that the currently audited package contains malicious code. The audited
setup.pycontains no malicious installation behavior, and the runtime implementation does not independently retrieve or execute remote payloads.Attack Path
- An attacker compromises the referenced GitHub repository, its maintainer account, or another mechanism capable of modifying the default branch.
- The attacker adds malicious runtime or package build code to that branch.
- A user follows the installation instructions and runs:
bash pip install git+https://github.com/minirr890112-byte/popular-web-designs.git - Pip retrieves the attacker-controlled branch state rather than the version reviewed in this audit.
- Malicious build or package code executes during installation or when the installed CLI is invoked.
Impact Assessment
Successful exploitation co ...[truncated 486 chars]
- Remediation
View remediation
Remediation Suggestions
-
Publish reviewed releases to a trusted Python package registry and instruct users to install an exact version:
bash pip install popular-web-designs==1.2.0 -
For reproducible deployments, provide a requirements file with cryptographic hashes and require hash verification:
bash pip install --require-hashes -r requirements.txt -
If installation directly from Git is necessary, pin the URL to a reviewed full commit SHA rather than a branch:
bash pip install "git+https://github.com/minirr890112-byte/popular-web-designs.git@FULL_REVIEWED_COMMIT_SHA" -
Protect release and repository integrity through mandatory multi-factor authentication, branch protection, reviewed pull requests, signed tags or commits, and restricted release credentials.
-
Update both
SKILL.mdandREADME.mdso that all primary installation examples use the immutable, verified source.
-
