T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Global Installation of Mutable Executable Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-22
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumbash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
Both documented installation methods retrieve mutable upstream content without pinning an audited version or verifying a checksum or signature. The Go command explicitly requests
@latest, while the npm command omits a version and therefore resolves the registry's current release.The npm command also installs the package globally. This exposes the user's broader environment to package installation behavior, including npm lifecycle scripts, and places the resulting executable in a user-wide or system-wide binary location. The installed CLI may subsequently have access to local PDF documents and the
MINERU_TOKENenvironment variable as part of its intended operation.This does not establish that the current upstream packages are malicious. The vulnerability is that future installations are not reproducible and may execute content different from the dependency version that was originally reviewed.
Attack Path
- An attacker compromises the relevant package registry account, source repository, release process, or transitive dependency.
- The attacker publishes a malicious release that becomes the current npm version or the Go module version resolved through
@latest. - A user or agent follows the installation instructions in
SKILL.md. - The package manager retrieves the mutable malicious release without an integrity value or audited version constraint.
- Malicious package lifecycle logic or executable code runs with the permissions of the installing user.
- The compromised dependency can access resources available to that process, potentially including local documents, environment variables such a ...[truncated 631 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to a specific, reviewed release rather than using an implicit current version or
@latest:bash npm install --save-exact mineru-open-api@AUDITED_VERSION go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@AUDITED_VERSION - Replace
AUDITED_VERSIONwith an actual immutable version or commit selected after security review. - Prefer a project-local npm installation or an isolated container or virtual environment instead of global installation.
- Publish and verify cryptographic checksums or signatures for approved release artifacts.
- Use lockfiles where applicable and review transitive dependencies and npm lifecycle scripts.
- Run the conversion CLI with least privilege and provide
MINERU_TOKENonly to the conversion process. - Avoid using
sudoor an administrative account for installation. - Document the expected package publisher, repository, version, and artifact digest so users can verify provenance before execution.
- Pin both installation methods to a specific, reviewed release rather than using an implicit current version or
