T08 · Insecure Dependencies
- Location
SKILL.md:60- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:60-63; additional occurrences atrealtime_finance.py:15-21andrealtime_finance.py:347-353
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:60-63:markdown ## 依赖 - Python 3 - yfinance: `pip3 install yfinance`realtime_finance.py:15-21:python try: import yfinance as yf YFINANCE_AVAILABLE = True except ImportError: YFINANCE_AVAILABLE = False print("⚠️ yfinance 未安装,美股数据将不可用") print("安装命令: pip3 install yfinance")realtime_finance.py:347-353:python if yahoo_codes: if not YFINANCE_AVAILABLE: print("\n⚠️ yfinance 未安装,无法获取美股数据") print("安装命令: pip3 install yfinance") returnTechnical Analysis
The project directs users to install
yfinancewithout specifying a reviewed version or verifying package integrity. The command resolves whichever release is currently provided by the configured Python package index.Python packages can execute installation or build-related code during installation. Consequently, compromise of the package distribution channel, a malicious package-index configuration, or an unsafe future release could result in code execution. The application itself does not automatically run the installation command; exploitation requires a user or administrator to follow the displayed instruction.
Attack Path
- The user invokes a Yahoo-backed query without
yfinanceinstalled. - The application displays
pip3 install yfinance, or the user follows the same instruction inSKILL.md. - The package manager resolves the dependency from the environment's configured index without a version pin or hash verification.
- A compromised index or package release supplies attacker-controlled package content.
- Installation or subsequent import executes that content with the privilege ...[truncated 518 chars]
- The user invokes a Yahoo-backed query without
- Remediation
View remediation
Remediation Suggestions
- Pin
yfinanceand all transitive dependencies to reviewed versions in a lock file. - Use hashes for downloaded distributions, such as a requirements file consumed with
python3 -m pip install --require-hashes -r requirements.txt. - Prefer an isolated virtual environment rather than installing into the system interpreter.
- Document and enforce a trusted HTTPS package index.
- Integrate dependency vulnerability and provenance scanning into release workflows.
- Replace both runtime installation messages with the secured, locked installation procedure.
- Periodically review and deliberately update the pinned dependency set rather than resolving the latest version at installation time.
- Pin
