T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependency Creates a Supply-Chain Risk
- Content
View full analysis
=5 ``` ### Technical Analysis The Skill instructs users to install a third-party package using a version constraint with no exact pin, upper bound, package hash, or locked artifact. The `>=5` constraint allows pip to select any current or future qualifying release from its configured package index. Because Python package installation and subsequent imports can execute package-controlled code, the effective code trusted by the Skill can change after this project has been reviewed. If a qualifying package release or the configured package index is compromised, installation or import of the resolved dependency could execute attacker-controlled code. This finding does not establish that the current `chardet` package is malicious. The vulnerability is the absence of controls ensuring that users receive the specific dependency artifact that was reviewed. ### Attack Path 1. An attacker compromises a future qualifying `chardet` release, its publisher account, a package mirror, or another package source configured in the victim's pip environment. 2. The victim follows the documented command: `python -m pip install -r requirements.txt`. 3. Pip resolves the attacker-controlled release because `chardet>=5` permits future versions. 4. Package-controlled code executes during installation or when `scripts/read_csv.py` imports `chardet`. 5. The malicious code acts with the permissions of the user running pip or the CSV-processing script. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the attacker ...[truncated 377 chars]- Remediation
View remediation
