T08 · Insecure Dependencies
- Location
scripts/book_extractor.py:14- Finding
Unpinned Third-Party Dependency Installation Guidance
- Content
View full analysis
Vulnerability Details
File Location:
scripts/book_extractor.py:14-20,scripts/book_extractor.py:33-42,scripts/book_extractor.py:51-62, andscripts/book_extractor.py:64-72
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
python def extract_text_from_pdf(file_path): """从PDF提取文本""" try: import PyPDF2 with open(file_path, 'rb') as f: reader = PyPDF2.PdfReader(f) text = "" for page in reader.pages: text += page.extract_text() + "\n" return text except ImportError: return "请安装 PyPDF2: pip install PyPDF2"python def extract_text_from_epub(file_path): """从EPUB提取文本""" try: import ebooklib from ebooklib import epub book = epub.read_epub(file_path) text = "" for item in book.get_items(): if item.get_type() == 9: # DOCUMENT text += item.get_content().decode('utf-8') + "\n" return text except ImportError: return "请安装 ebooklib: pip install ebooklib"python def extract_text_from_mobi(file_path): """从MOBI提取文本""" try: import mobi from pathlib import Path output_path = Path(file_path).with_suffix('.html') mobi.extract(file_path, output_path) with open(output_path, 'r', encoding='utf-8') as f: text = f.read() # 清理临时文件 output_path.unlink(missing_ok=True) return text except ImportError: return "请安装 mobi: pip install mobi"python def extract_text_from_docx(file_path): """从DOCX提取文本""" try: import docx doc = docx.Document(file_path) text = "" for para in doc.paragraphs: text += para.text + "\n" return text ...[truncated 1984 chars]- Remediation
View remediation
Remediation Suggestions
- Add a reviewed dependency manifest containing exact versions for all runtime and transitive dependencies.
- Generate and verify cryptographic hashes, then install with a command such as
pip install --require-hashes -r requirements.txt. - Use a lock-file workflow appropriate to the selected package manager.
- Install packages only from explicitly trusted repositories and disable unintended extra indexes.
- Perform dependency vulnerability and provenance scanning in CI.
- Replace the unconstrained installation messages with instructions referencing the project's locked installation process.
- Run document parsers in an isolated, least-privileged environment because they process attacker-controlled file formats.
