T08 · Insecure Dependencies
- Location
scripts/main.py:14- Finding
Unpinned Automatic Runtime Dependency Installation
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/main.py:14-23scripts/submit_job.py:13-22scripts/query_job.py:14-23
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: MediumAffected code in
scripts/main.py:python def ensure_dependencies(): try: import tencentcloud.ai3d # noqa: F401 except (ImportError, ModuleNotFoundError): print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)Affected code in
scripts/submit_job.py:python def ensure_dependencies(): try: import tencentcloud.ai3d # noqa: F401 except (ImportError, ModuleNotFoundError): print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)Affected code in
scripts/query_job.py:python def ensure_dependencies(): try: import tencentcloud.ai3d # noqa: F401 except (ImportError, ModuleNotFoundError): print("[INFO] tencentcloud-sdk-python (ai3d) not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", ...[truncated 2664 chars]- Remediation
View remediation
Remediation Suggestions
- Remove automatic dependency installation from all executable scripts. If the SDK is unavailable, terminate with a clear error that directs the operator to the documented installation procedure.
- Declare an exact, reviewed SDK version in project dependency metadata rather than resolving the latest release:
text tencentcloud-sdk-python==<audited-version> - Generate and commit a lockfile containing cryptographic hashes. Install dependencies during a controlled deployment stage with hash verification, such as:
bash python -m pip install --require-hashes -r requirements.txt - Use a trusted, explicitly configured HTTPS package index or an internally controlled artifact repository.
- Perform dependency installation in an isolated virtual environment or container under a least-privilege account.
- Add automated dependency vulnerability and integrity scanning to the release process.
- Use short-lived Tencent Cloud credentials with narrowly scoped permissions so dependency compromise cannot expose long-lived or broadly privileged credentials.
