T08 · Insecure Dependencies
- Location
scripts/setup.sh:14- Finding
Unpinned Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.sh, line 14
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
bash "$VENV/bin/pip" install --quiet pyairbnb curl-cffiTechnical Analysis
The setup script installs
pyairbnbandcurl-cffiwithout exact version constraints, a lock file, or package hash verification. Consequently, each fresh installation resolves whatever package versions and transitive dependencies are available from the configured Python package index at that time.This does not establish that either dependency is currently malicious. However, it creates a supply-chain exposure because the installed code may differ from the code reviewed or tested by the project author. A compromised package release, compromised maintainer account, unsafe package-index configuration, or malicious transitive dependency could introduce attacker-controlled code. Python packages may execute code during installation, and imported packages execute code within the application process at runtime.
Attack Path
- An attacker compromises a dependency, one of its transitive dependencies, its maintainer account, or the package distribution channel.
- The attacker publishes a malicious version that still satisfies the unconstrained package names.
- A user performs a fresh setup by running
bash scripts/setup.sh. pipresolves and installs the malicious or compromised release because no approved versions or hashes are enforced.- Malicious code executes during package installation or when
search.pyimportspyairbnbordetails.pyimportscurl_cffi. - The code operates with the privileges of the user running the setup or application.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the installing or executing user. Depending on those privileges and the host environment, the attacker could read or modify user-accessible ...[truncated 365 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin all direct and transitive dependencies to reviewed versions in a lock file.
- Generate and verify cryptographic hashes for every package artifact.
- Install dependencies using hash enforcement, for example:
bash "$VENV/bin/pip" install --require-hashes -r requirements.txt- Maintain a
requirements.txtor equivalent lock file containing exact versions and hashes, such as:
text pyairbnb==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH curl-cffi==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH- Include all transitive dependencies in the lock file rather than allowing them to resolve dynamically.
- Review dependency changes and security advisories before deliberately updating the lock file.
- Use a trusted package index explicitly and protect build environments from user-controlled pip configuration or index overrides.
- Consider installing from pre-vetted artifacts in a controlled internal repository for higher-assurance deployments.
