T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Playwright Dependency and Browser Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–21
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Mediumbash npm install playwright npx playwright install chromiumTechnical Analysis
The installation instructions retrieve Playwright and its Chromium browser components without specifying an exact package version, lockfile, integrity hash, or trusted registry configuration. Consequently, the effective components installed when a user follows these instructions may differ from those reviewed during the audit.
The unqualified
npm install playwrightcommand resolves a mutable package version according to npm registry state and local configuration. Package installation can run npm lifecycle scripts with the privileges of the invoking user. The subsequentnpx playwright install chromiumcommand also downloads a browser binary associated with the resolved Playwright release.Exploitation requires compromise or malicious substitution within the dependency delivery chain, such as a compromised package release, registry or configuration manipulation, or another supply-chain failure. The audit found no evidence that the current Playwright package itself is malicious; the risk arises from installation instructions that do not provide reproducible or integrity-verified dependency resolution.
Attack Path
- An attacker compromises a package release or influences the npm dependency-resolution path or configured registry.
- A user follows the documented prerequisite and runs
npm install playwright. - npm resolves and installs the attacker-controlled or compromised component because no audited version or lockfile constrains resolution.
- Malicious package lifecycle code may execute during installation with the privileges of the user running npm.
- Alternatively, the following
npx playwright install chromiumcommand may retrieve an unexpected browser artifa ...[truncated 639 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Playwright to a reviewed exact version rather than relying on the current registry default:
bash npm install --save-exact playwright@<reviewed-version> - Commit
package.jsonandpackage-lock.json, including npm integrity metadata, to make dependency resolution reproducible. - In automated or production environments, use
npm ciagainst the committed lockfile instead of an unconstrainednpm install. - Configure npm to use an explicitly trusted registry and verify that project-level or user-level npm configuration cannot redirect dependency retrieval to an untrusted source.
- Review dependency changes and browser-binary updates before modifying the pinned version or lockfile.
- Run installation and browser automation as a dedicated, non-privileged user in an isolated environment with only the filesystem and network access required for the task.
- Where supported by the delivery process, verify downloaded package and browser artifact provenance or checksums.
- Pin Playwright to a reviewed exact version rather than relying on the current registry default:
