T08 · Insecure Dependencies
- Location
browse.js:119- Finding
Runtime Dependencies Are Retrieved and Executed Without Immutable Verification
- Content
View full analysis
Vulnerability Details
File Location:
browse.js:5-6,browse.js:119-122
Vulnerability Type: Supply-chain exposure through mutable container and npm dependencies
Risk Level: MediumVulnerable Code
js const IMAGE = 'mcr.microsoft.com/playwright:v1.50.0-noble'; const PLAYWRIGHT_VERSION = '1.50.0';js IMAGE, '/bin/bash', '-c', `cd /tmp && npm init -y >/dev/null 2>&1 && npm install playwright@${PLAYWRIGHT_VERSION} >/dev/null 2>&1 && node -e '${playwrightScript.replace(/'/g, "'\\''")}'`Technical Analysis
Each invocation executes
npm install playwright@1.50.0inside a newly created container. Although an explicit package version is specified, the installation does not use a committed lockfile, a verified package integrity hash, or an internally reviewed package artifact. The npm client may also execute package lifecycle scripts during installation.The Playwright container is identified by the mutable tag
v1.50.0-noblerather than an immutable image digest. Consequently, the effective image executed by the skill could change if that tag is replaced or the upstream registry is compromised.This behavior creates a supply-chain trust dependency at runtime: code retrieved after the project has been audited is installed and executed automatically.
Attack Path
- An attacker compromises the upstream npm package, npm registry resolution path, container registry, or mutable image tag.
- A user invokes
browse.jsfor an otherwise legitimate browsing operation. - Podman retrieves the mutable container image when it is unavailable locally or an updated image is requested.
- The container runs
npm install playwright@1.50.0without validating a project-controlled integrity record. - Altered package code or lifecycle scripts execute inside the container.
- The malicious dependency can access the container's network, environment, browser process, and generated browsing res ...[truncated 774 chars]
- Remediation
View remediation
Remediation Suggestions
- Build and publish a reviewed application image that already contains the required Playwright package instead of installing it on every invocation.
- Pin the container image by immutable digest, for example:
js const IMAGE = 'mcr.microsoft.com/playwright@sha256:<verified-digest>'; - Commit a
package-lock.jsongenerated from a trusted environment and usenpm cirather thannpm install. - Verify dependency integrity in CI and before image publication.
- Disable lifecycle scripts with
--ignore-scriptsif Playwright installation does not require them in the selected image. - Scan the finished image and dependency tree for known vulnerabilities.
- Prefer an internally mirrored or allowlisted registry and enforce image-signature verification.
- Define a controlled update process so dependency and image changes receive review before deployment.
