T08 · Insecure Dependencies
- Location
install.py:12- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
install.py:12-18, 43-54
Vulnerability Type: Uncontrolled third-party dependency resolution
Risk Level: MediumComplete Code Snippet
python PACKAGES = [ ("pptx", "python-pptx", True), ("fitz", "PyMuPDF", True), ("docx", "python-docx", True), ("PIL", "Pillow", True), ("matplotlib", "matplotlib", False), ] def install_missing(missing): """pip install ONLY the missing packages. Only missing packages are installed to avoid uninstalling or reinstalling packages that are already present. """ print("\nInstalling missing dependencies...") cmd = [ sys.executable, "-m", "pip", "install", "--no-input", "--disable-pip-version-check", ] + [pip_name for pip_name, _ in missing] result = subprocess.run(cmd, capture_output=True, text=True)Technical Analysis
The installer invokes pip using package names without exact version constraints, package hashes, a lockfile, or an explicitly trusted package index. Dependency resolution therefore selects whichever compatible releases and transitive dependencies are available from the configured index at installation time.
Python package installation can execute package build or installation logic. Consequently, the effective code installed by this project can change after the project itself has been reviewed. This is a supply-chain weakness rather than evidence that the currently named packages are malicious.
Attack Path
- An attacker compromises a named package, one of its transitive dependencies, or the package index used by the environment.
- The attacker publishes or substitutes a malicious release that remains compatible with the unpinned installation request.
- A user runs
python install.pywhile the affected dependency is missing. - The installer invokes pip and resolves the attacker-controlled release.
- Package build or installation logic executes with the privileges of the u ...[truncated 731 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed exact version.
- Include transitive dependencies in a generated lockfile.
- Require verified hashes, for example with
pip install --require-hashes -r requirements.txt. - Use an explicitly configured and trusted package index or an internally controlled package mirror.
- Perform installation in an isolated virtual environment with ordinary user privileges.
- Separate dependency checking from installation and require explicit user approval before downloading or installing packages.
- Add automated dependency vulnerability and provenance scanning to the release process.
- Periodically update pinned versions through a controlled review and testing workflow.
