T08 · Insecure Dependencies
- Location
README.md:91- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 91
Vulnerability Type: Unpinned third-party dependency
Risk Level: Lowbash pip install numpyTechnical Analysis
The installation instructions resolve
numpywithout a version constraint, lockfile, or cryptographic hash. Consequently, installations performed at different times may retrieve different package releases. This weakens build reproducibility and prevents users from verifying that the installed artifact is the dependency version reviewed and tested with this project.The package name refers to the expected public dependency, and the project does not use an apparent typosquatted name or an untrusted package index. Exploitation therefore requires the selected package source or a subsequently resolved release to be compromised. This is a supply-chain hardening issue rather than evidence that the current dependency is malicious.
Attack Path
- A user follows the installation command from
README.md. pipresolves the latest compatiblenumpydistribution from the configured package index.- If that index, the package release, the user's package-index configuration, or the distribution artifact has been compromised, an attacker-controlled artifact is downloaded.
- Malicious behavior may execute during package installation or when the application later imports
numpy. - The payload runs with the privileges of the user performing the installation or launching the application.
Impact Assessment
A successful supply-chain compromise could execute arbitrary code under the installing user's account. This could expose files and credentials accessible to that account, modify user-owned data, or affect subsequent application execution. System-wide impact would require the user to install the dependency with elevated privileges; the documented command itself does not request elevation. No direct dependency compromise, remote payl ...[truncated 90 chars]
- A user follows the installation command from
- Remediation
View remediation
Remediation Suggestions
- Declare an explicitly tested
numpyversion or bounded compatible version range. - Generate and commit a lockfile containing exact transitive dependency versions.
- Require cryptographic hashes for installation artifacts, for example through a hash-locked requirements file and
pip install --require-hashes. - Install from the official Python Package Index or a controlled internal mirror, and document the expected package source.
- Integrate dependency vulnerability and integrity scanning into the release process.
- Avoid recommending installation with administrator or root privileges.
- Declare an explicitly tested
