T08 · Insecure Dependencies
- Location
README.md:12- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md:12-14
Vulnerability Type: Supply-chain dependency risk
Risk Level: Lowbash pip install requestsTechnical Analysis
The installation instructions request the latest package version available under the
requestsname without a version constraint or integrity hash. This produces non-reproducible installations and leaves future deployments exposed to compromised releases, unexpected transitive dependency changes, or incompatible updates.No malicious or typosquatted dependency was identified in the audited project. The risk arises from resolving an uncontrolled future package version rather than from a currently confirmed malicious package.
Attack Path
- A user follows the documented installation command.
- The package installer queries its configured package index.
- An uncontrolled current or future version of
requestsand its transitive dependencies is selected. - If a selected release or configured package index is compromised, malicious package installation or import behavior executes with the privileges of the user running
pip. - The malicious dependency could access files, credentials, and network resources available to that user.
Impact Assessment
Successful supply-chain exploitation could execute code with the privileges of the account or environment performing the installation. In a user-level virtual environment, access would generally be limited to that user's accessible files and resources. Running package installation as an administrator would significantly increase the impact. The project itself does not request elevated installation privileges.
- Remediation
View remediation
Remediation Suggestions
- Declare a reviewed, exact dependency version in a dedicated requirements file.
- Pin all transitive dependencies where reproducible builds are required.
- Generate and verify cryptographic hashes, then install with
pip install --require-hashes -r requirements.txt. - Use an isolated virtual environment rather than a global Python installation.
- Configure trusted package indexes explicitly and avoid unreviewed mirrors.
- Periodically update pinned versions after vulnerability and compatibility review.
