T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Global Installation of a Mutable Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 14
Vulnerability Type: Supply-chain exposure through an unpinned dependency
Risk Level: MediumComplete Code Snippet:
bash npm install -g @playwright/cli@latest playwright-cli --helpTechnical Analysis
The setup instructions install
@playwright/cliusing the mutablelatestnpm tag. This does not guarantee that users receive the same reviewed package version each time the command is executed. No lockfile, exact version, or package-integrity value constrains the resolved artifact.The global installation scope increases the potential impact because the package and its executable are installed into the user's global npm environment. npm package installation can also invoke package lifecycle scripts under the privileges of the user running npm. There is no evidence that the current upstream package is malicious; the vulnerability is the uncontrolled trust placed in whichever release the
latesttag resolves to at installation time.Attack Path
- An attacker compromises the upstream npm package, a maintainer account, or the package publication process.
- The attacker publishes a modified release and causes the
latesttag to resolve to it. - A user follows the documented setup command.
- npm downloads and installs the attacker-controlled release globally.
- Malicious lifecycle or runtime code executes with the privileges of the installing user when installation occurs or when
playwright-cliis invoked.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Depending on those privileges, the malicious package could access user-readable files and credentials, alter the user's global npm environment, replace the installed CLI, or affect subsequent browser-automation operations. If the command is run with elevated privileges, the scope could exte ...[truncated 50 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed version, such as@playwright/cli@X.Y.Z. - Prefer a project-local dependency managed by a committed lockfile rather than a global installation.
- Use
npm ciin automated environments to enforce lockfile-resolved versions. - Verify package provenance and registry integrity before updating the pinned version.
- Review release notes and package contents before changing the approved version.
- Avoid running npm installation commands with elevated privileges.
- Where supported, enforce trusted registries, package allowlists, and dependency-scanning controls.
- Replace
