T08 · Insecure Dependencies
- Location
install.sh:26- Finding
Unpinned Dependency Installation Enables Supply-Chain Substitution
- Content
View full analysis
=1.3.0 numpy>=1.21.0 openpyxl>=3.0.0 matplotlib>=3.4.0 seaborn>=0.11.0 ``` ### Technical Analysis The installation script requests packages by name without exact versions or package hashes. Consequently, the installed code depends on the state of the configured Python package index at installation time. Python packages may execute packaging hooks during installation, and their modules subsequently run with the privileges of the user invoking the skill. The absence of an isolated virtual environment also means the installation modifies the active Python environment. The package names are established packages, and the audit found no direct evidence of typosquatting or a currently malicious dependency. The security issue is the lack of reproducibility and integrity enforcement. Relevant compromise scenarios include: - A compromised upstream publisher account or malicious future package release. - A user or system configured to use an untrusted `PIP_INDEX_URL` or additional package index. - Dependency resolution selecting a vulnerable or behaviorally incompatible future release. - Installation into a privileged or shared Python environment, increasing the effect of package compromise. ### Attack Path 1. An attacker compromises a package publisher, package-index account, or package source configured on the target. 2. The attacker publishes a malicious version satisfying the unrestricted dependency request. 3. A user runs `install.sh`. 4. `pip3 install` resolves and downloads the attacker-controlled release. 5. ...[truncated 776 chars]- Remediation
View remediation
