T08 · Insecure Dependencies
- Location
SKILL.md:59- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Exposure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56-60
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
markdown ## Dependencies ```bash pip install pandas numpy requeststext ### Technical Analysis The installation instruction retrieves the latest available versions of `pandas`, `numpy`, and `requests` without version constraints, integrity hashes, or a reviewed lock file. Consequently, installations are not reproducible and the package contents may differ from those originally audited. Python package installation can execute package-controlled build or installation logic. If a dependency release or its package-distribution account is compromised, following this instruction could run attacker-controlled code with the privileges of the user performing the installation. The listed package names are established packages rather than apparent typosquatting or dependency-confusion names. Therefore, exploitation depends on an upstream repository, maintainer account, release, or delivery-path compromise; the project itself does not contain a malicious dependency. ### Attack Path 1. An attacker compromises an upstream dependency release, maintainer account, or package-distribution channel. 2. A malicious version is published under one of the dependency names. 3. A user follows the documented unpinned `pip install` command. 4. `pip` resolves the compromised release because no approved version or hash is enforced. 5. Malicious build, installation, or imported runtime code executes in the user's Python environment. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the user running `pip`. Depending on those privileges, this could permit access to user-readable files, modification of the active Python environment, credential theft, or further system compromise. No privilege escalation is inherent in th ...[truncated 187 chars]- Remediation
View remediation
Remediation Suggestions
- Move dependencies into a reviewed requirements or lock file with exact versions.
- Record cryptographic hashes and require hash verification during installation:
bash python -m pip install --require-hashes -r requirements.txt - Generate the lock file from a trusted environment and review transitive dependencies.
- Use an isolated virtual environment rather than installing into a system-wide interpreter.
- Configure a trusted package index explicitly where appropriate.
- Automate dependency vulnerability scanning and controlled update review.
- Avoid recommending installation with administrator privileges.
