T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned Third-Party Packages and Mutable Container Image
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-32
Vulnerability Type: Unpinned executable dependencies
Risk Level: MediumComplete Code Snippet:
bash pip install vllm # 需要 CUDA 12.1+ # Docker 部署(推荐生产环境) docker run --runtime nvidia --gpus all \ -v ~/.cache/huggingface:/root/.cache/huggingface \ -p 8000:8000 vllm/vllm-openai:latest \ --model meta-llama/Llama-3.1-8B-InstructTechnical Analysis
The installation instructions execute third-party artifacts without pinning them to immutable, audited versions.
pip install vllmallows the package manager to select the current compatible vLLM release and its transitive dependencies. The Docker instruction similarly uses the mutablelatesttag rather than an immutable image digest.Consequently, the effective code executed by these commands may change after the Skill has been reviewed. If a package maintainer account, package registry, container registry, release pipeline, or transitive dependency is compromised, following the documented commands could install and execute attacker-controlled code.
The container is additionally granted access to all NVIDIA GPUs and write access to the host's Hugging Face cache through the bind mount. These permissions increase the impact of a compromised image.
Attack Path
- An attacker compromises a relevant package, transitive dependency, registry account, container image, or release pipeline.
- The attacker publishes a malicious release that satisfies the unpinned
piprequest or replaces the image referenced by the mutablelatesttag. - A user follows the instructions in
SKILL.md. - The package installer or container runtime retrieves the altered artifact.
- Attacker-controlled code runs with the invoking user's package-installation privileges or inside a GPU-enabled container.
- In the Docker scenario, the malicious process can consume GPU resources and read or ...[truncated 736 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin vLLM to a reviewed, exact version, such as
vllm==<approved-version>. - Use a lock file or constraints file with cryptographic hashes for vLLM and all transitive Python dependencies.
- Install only from explicitly trusted package indexes and verify release provenance where available.
- Replace
vllm/vllm-openai:latestwith an approved version tag and an immutable digest, for examplevllm/vllm-openai:<version>@sha256:<verified-digest>. - Scan container images and Python dependencies for known vulnerabilities before deployment.
- Run the container as a non-root user where supported.
- Mount the Hugging Face cache read-only unless writes are operationally necessary, or use a dedicated cache containing no unrelated credentials or sensitive artifacts.
- Limit GPU and filesystem access to the minimum required for the selected model.
- Pin vLLM to a reviewed, exact version, such as
