T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 22-25
Vulnerability Type: Supply-chain exposure through an unpinned dependency
Risk Level: MediumVulnerable Code
bash Install the requests package: ```bash pip install requeststext ### Technical Analysis The installation instructions retrieve and install the latest version of `requests` available from pip's configured package index. No reviewed version, lock file, package hash, or trusted index is specified. This does not demonstrate that the current `requests` package is malicious. However, it makes installation behavior dependent on mutable upstream package metadata and the user's pip configuration. A compromised upstream release, maliciously configured package index, or future package version could introduce unwanted code. Python package installation may execute package-controlled build logic under the privileges of the user running pip. ### Attack Path 1. An attacker compromises an upstream release or a package index used by the victim. 2. The victim follows the documented `pip install requests` instruction. 3. pip resolves a mutable, unreviewed package version from the configured index. 4. Package-controlled installation or build logic executes. 5. Malicious code gains the permissions of the account or environment running pip. This path depends on an upstream or package-index compromise; the audited project does not itself supply a malicious dependency. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the user performing installation. Depending on the environment, this may permit access to that user's files, environment variables, API credentials, virtual environment, and application data. If installation is performed by a privileged account, the impact could extend to system-level modification.- Remediation
View remediation
Remediation Suggestions
-
Pin
requeststo a reviewed version in a requirements or lock file. -
Record and verify package hashes using
pip install --require-hashes. -
Install only from an explicitly trusted package index.
-
Prefer installation inside an isolated virtual environment under an unprivileged account.
-
Use automated dependency scanning and controlled update procedures to review future version changes.
-
Example hardened command:
bash python3 -m pip install --require-hashes -r requirements.txt
-
