T08 · Insecure Dependencies
- Location
SKILL.md:586- Finding
Unpinned Third-Party Package and Source Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 586-604
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
bash # Basic installation (CPU, ONNX backend) pip install openocr-python # GPU-accelerated ONNX inference pip install openocr-python[onnx-gpu] # PyTorch backend (for server mode) pip install openocr-python[pytorch] # Gradio demos pip install openocr-python[gradio] # All optional dependencies pip install openocr-python[all] # From source git clone https://github.com/Topdu/OpenOCR.git cd OpenOCR python build_package.py pip install ./build/dist/openocr_python-*.whlTechnical Analysis
The installation instructions do not pin an exact package version, dependency lockfile, artifact hash, or Git commit. Consequently, the effective code installed by these commands can change after the Skill has been audited.
Installing the package from PyPI may execute package build or installation hooks and install mutable transitive dependencies. The source-installation path clones the repository's current default branch, executes
build_package.py, and installs the resulting wheel. Although the documented repository is consistent with the declared OpenOCR project, its default branch remains mutable.This is a supply-chain weakness rather than evidence that the current OpenOCR package is malicious.
Attack Path
- An attacker compromises the upstream package account, source repository, release process, or a transitive dependency.
- The attacker publishes a modified package or commits malicious code to the mutable branch used by the instructions.
- A user follows the documented
pip installorgit cloneinstallation procedure. - The compromised package, build script, or installation hook executes on the user's system.
- The payload receives the privileges of the account performing the installation.
Impac
...[truncated 531 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
openocr-pythonand every required dependency to reviewed versions. - Use a lockfile containing cryptographic hashes, or install with pip hash verification.
- Pin source installations to a reviewed full Git commit hash rather than the default branch.
- Verify release signatures or checksums before installation.
- Review
build_package.pyand package installation hooks before executing them. - Install dependencies in an isolated virtual environment or container under a non-privileged account.
- Avoid administrator or root installation unless it is strictly necessary.
- Establish a controlled update process in which new dependency versions are reviewed before adoption.
- Pin
