T08 · Insecure Dependencies
- Location
references/install_ocr.md:4- Finding
Unverified and Unpinned Third-Party Software Installation
- Content
View full analysis
Vulnerability Details
File Location:
references/install_ocr.md, lines 4 and 14–15; also referenced byscripts/ocr_batch.py, line 13
Vulnerability Type: Insecure third-party dependency installation
Risk Level: MediumVulnerable Code Snippets
references/install_ocr.md, line 4:text 1. 前往 https://github.com/UB-Mannheim/tesseract/wiki 下载对应 Windows 的 MSI 安装包(通常是 `tesseract‑5.3.1‑setup‑amd64.exe`)。references/install_ocr.md, lines 14–15:powershell python -m pip install --upgrade pip pip install ocrmypdfscripts/ocr_batch.py, line 13:python " pip install ocrmypdf\n"Technical Analysis
The installation documentation instructs users to download and execute a community-distributed Windows installer without providing an immutable artifact URL, expected cryptographic hash, or digital-signature verification procedure. It also installs the latest available
ocrmypdfpackage and its transitive dependencies from PyPI without pinning or lock-file verification.The GitHub wiki is relevant to the OCR software and is not inherently malicious. Nevertheless, the installation process trusts mutable external content. If the hosting account, release artifact, package, or a transitive dependency were compromised or substituted, malicious code could execute during installation or later when the OCR command is invoked.
Upgrading
pipis not required for the Skill's declared OCR functionality and increases the number of components modified. The runtime script itself does not download software automatically; this risk arises when users follow the documented setup instructions.Attack Path
- An attacker compromises or substitutes the referenced installer, the
ocrmypdfpackage, or one of its transitive dependencies. - A user follows the Skill documentation and downloads the executable or runs the unpinned
pip installcommand. - The unverified installer, package build process, or package initialization code ex ...[truncated 1095 chars]
- An attacker compromises or substitutes the referenced installer, the
- Remediation
View remediation
Remediation Suggestions
- Pin the supported
ocrmypdfversion and all transitive Python dependencies in a reviewed lock file with hashes. - Replace mutable download guidance with a specific HTTPS release URL from a trusted project-controlled source.
- Publish the expected SHA-256 digest for the Windows installer and instruct users to verify it before execution.
- Document how to validate the installer's Authenticode signature and expected publisher identity.
- Recommend installation in a dedicated virtual environment rather than modifying a global Python environment.
- Remove the unconditional
python -m pip install --upgrade pipinstruction unless a documented minimum version is required. - Prefer invoking
python -m pipconsistently so dependencies are installed into the intended interpreter. - Update the runtime error message to refer users to the pinned, integrity-verified installation procedure rather than suggesting an unpinned installation command.
- Clarify that normal OCR processing is local, while initial dependency installation requires network access and involves third-party supply-chain trust.
- Pin the supported
