T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–18
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Mediumbash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The installation instructions retrieve and execute third-party software without pinning it to a reviewed, immutable version. The npm command resolves the package version available under the package registry's current default tag, while the Go command explicitly requests
@latest.Consequently, the installed code can change without any corresponding modification to this skill. If the package publisher account, source repository, package registry, or release pipeline is compromised, a malicious release could be delivered to users following these instructions. npm lifecycle scripts or Go build-time behavior may execute during installation, and the resulting CLI executes with the privileges of the invoking user.
The npm command also requests a global installation. Depending on the host's npm configuration, users may run it with elevated privileges, which would increase the potential impact. The documentation does not explicitly instruct users to use elevated privileges, so privilege escalation is not treated as a confirmed behavior.
Attack Path
- An attacker compromises the upstream package publisher, repository, registry account, or release pipeline.
- The attacker publishes a malicious version of
mineru-open-apior modifies the release resolved by@latest. - A user follows the documented installation command.
- The package manager retrieves the malicious release because no reviewed version or integrity value is pinned.
- Malicious code executes during installation or when the installed CLI is invoked.
- The code gains access to resources available to the invoking user, potentially including submitted presentation files, generate ...[truncated 809 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to specific versions that have been reviewed:
bash npm install -g mineru-open-api@<reviewed-version> go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@<reviewed-version> - Prefer immutable release identifiers, such as a verified semantic version or commit digest, rather than
latestor an implicit registry tag. - Publish expected package checksums or signature-verification instructions and require verification before installation.
- Use dependency lockfiles and integrity metadata where installation is managed by a project rather than performed globally.
- Avoid global npm installation when possible. Use a project-local dependency or an isolated container or virtual environment with minimal filesystem and network permissions.
- Do not run installation commands with administrative privileges unless strictly necessary.
- Document a controlled upgrade process in which new releases are reviewed, verified, and tested before updating the pinned version.
- Run the OCR CLI with only the minimum required access and avoid exposing unrelated credentials in its environment.
- Pin both installation methods to specific versions that have been reviewed:
