T08 · Insecure Dependencies
- Location
references/python-pptx-render-qa-first-pass.md:8- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
references/python-pptx-render-qa-first-pass.md, line 8
Vulnerability Type: Supply-chain exposure through unpinned third-party packages
Risk Level: MediumComplete Snippet:
markdown - `python3 -m venv` + local installs (`pymupdf`, `python-pptx`, `pillow`, `markitdown`) solved missing-PyMuPDF problems without relying on system Python.Technical Analysis
The workflow recommends installing four third-party Python packages but does not specify exact versions, package hashes, a lockfile, or an explicitly trusted package index. A virtual environment provides dependency isolation but does not verify package provenance or integrity.
If an agent interprets this note as an instruction to install the latest available packages, dependency contents may change between runs. A compromised package release, malicious package-index configuration, dependency-confusion condition, or transitive dependency compromise could introduce attacker-controlled code. Python packages can execute code during build or installation, and imported packages execute code with the privileges of the invoking process.
No malicious package, repository, or installation command is embedded in the audited project. This finding concerns the unsafe reproducibility and supply-chain characteristics of the documented installation practice.
Attack Path
- An agent encounters a system where one or more listed packages are unavailable.
- Following the reference, it creates a virtual environment and installs the packages by name without version or hash verification.
- The package resolver contacts the configured package index and selects the currently available releases and transitive dependencies.
- An attacker compromises a selected release, dependency, or package source, or exploits an unsafe index configuration.
- Attacker-controlled build, installation, or import-time code executes under the account running the slide-generation ...[truncated 798 chars]
- Remediation
View remediation
Remediation Suggestions
- Add a reviewed dependency manifest or lockfile containing exact package and transitive-dependency versions.
- Record cryptographic hashes and install with hash enforcement, such as
pip install --require-hashes -r requirements.txt. - Configure and document an approved HTTPS package index rather than relying on an arbitrary environment-level index configuration.
- Disable unnecessary fallback indexes and review protections against dependency confusion.
- Prefer prebuilt, verified wheels where practical, and avoid executing unreviewed source builds.
- Scan and periodically update the locked dependency set through a controlled review process.
- Run document processing in a least-privileged, isolated environment without credentials or unrelated sensitive files.
- Revise the reference so it points to the pinned manifest instead of recommending package-name-only installation.
