T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Mutable and Unverified Third-Party SDK Dependency
- Content
View full analysis
=0.0.2,<1.0.0 ``` The dependency is subsequently installed and imported through the documented workflow: ```bash pip install -r requirements.txt python scripts/check_install.py ``` ### Technical Analysis The requirement is described as a reproducibility pin, but `>=0.0.2,<1.0.0` permits package managers to install any compatible future release below version 1.0.0. It is therefore a mutable version range rather than an exact pin. The source code of `cutrix-video-translate-sdk` is not included in the audited project. Consequently, the behavior of the installed package—including its installation process, module initialization, network activity, and access to environment variables—cannot be verified from this artifact. No package hashes are provided to authenticate the selected distribution artifact. After installation, `scripts/check_install.py` executes `import cutrix`. Python imports execute package-level initialization code, so a compromised or malicious package release satisfying the version range could run code in the current process. This finding does not establish that the current SDK release is malicious; it identifies the absence of controls preventing a future or substituted compatible release from being installed and executed. ### Attack Path 1. An attacker compromises the upstream publisher account, package distribution infrastructure, or a future release of `cutrix-video-translate-sdk`. 2. The attacker publishes a malicious version that satisfies `>=0.0.2,<1.0.0`. 3. A user or agent runs `pip install -r requirements.txt`. 4. The package resolver selects and installs the malicious compatible version. 5. Inst ...[truncated 1010 chars]- Remediation
View remediation
