T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Third-Party OCR Dependencies
- Content
View full analysis
-m pip install rapidocr onnxruntime` with the interpreter they intend to use. ``` `README.md:24`: ```bash python -m pip install rapidocr onnxruntime ``` ### Technical Analysis The documented installation commands install `rapidocr` and `onnxruntime` without fixed versions or package integrity hashes. Consequently, the exact code installed depends on whichever package releases the configured Python package index serves at installation time. Python packages can execute code during installation, and their modules execute code when imported. In this project, `run_rapidocr.py` imports `RapidOCR` from the installed `rapidocr` package and initializes the OCR engine. A compromised upstream release, package repository, mirror, or dependency in the transitive dependency graph could therefore introduce code that was not included in this audit. This issue does not demonstrate that the currently published dependencies are malicious. The risk arises because the documented process does not provide reproducible, integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises a future release of `rapidocr`, `onnxruntime`, or one of their transitive dependencies, or compromises a package index or mirror used by the victim. 2. A user follows the project's documented unpinned installation command. 3. `pip` resolves and downloads the attacker-controlled release because no reviewed version or artifact hash is required. 4. Malicious package logic executes during installation or when `run_rapidocr.py` imports and initializes the dependency. 5. The malicious code runs with the operating-system privileges and environmental access of the user invoking `pip` or the OCR skill. # ...[truncated 651 chars]- Remediation
View remediation
onnxruntime== ``` 2. Generate a lock or requirements file that includes resolved transitive dependencies and cryptographic hashes for approved artifacts. 3. Install dependencies using hash verification: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Maintain separate reviewed lock files where operating-system, architecture, or Python-version differences require different `onnxruntime` artifacts. 5. Configure installation to use a trusted package index or an internally controlled package mirror rather than arbitrary user-configured sources. 6. Add automated dependency vulnerability and provenance scanning to the release process. Review and regenerate pins deliberately when upgrading. 7. Update both `SKILL.md` and `README.md` so users are directed to the integrity-verified requirements file rather than an unpinned `pip install` command. ]]>
