T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Execution of an Unpinned Third-Party Container Image
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-24; duplicated inREADME.md:8-12
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code:
bash docker run -d -p 28642:8000 zhaoolee/bbduck:latestTechnical Analysis
The documented installation procedure executes the third-party container image
zhaoolee/bbduck:latest. Thelatesttag is mutable and does not identify a fixed, previously reviewed image. Its contents can change after this Skill has been audited without any corresponding change to the repository.If the image publisher account, registry, or build pipeline is compromised—or if the publisher replaces the image—the same documented command will download and execute different code. The project provides no immutable digest, signature-verification procedure, software bill of materials, or documented trust policy for this image.
The image executes inside a container, which ordinarily limits its privileges. However, it still processes user-supplied local images, can communicate over the network according to the runtime configuration, and exposes an HTTP service on the host. Host compromise is not established by the reviewed files and would require an additional container-runtime vulnerability or unsafe runtime privileges.
Attack Path
- An attacker compromises the image publisher account, image registry, or upstream container build process.
- The attacker publishes a modified image under
zhaoolee/bbduck:latest. - A user follows the documented
docker runcommand. - Docker resolves the mutable tag and downloads the attacker-controlled image.
- Malicious code runs in the container and receives images submitted to the compression API.
- The malicious container may disclose uploaded content, return manipulated output, attack network-reachable services, or consume host resources within the limits imposed by Docker.
Impact Assessment
S ...[truncated 636 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the mutable tag with a reviewed immutable digest:
bash docker run -d \ -p 127.0.0.1:28642:8000 \ zhaoolee/bbduck@sha256:<verified-image-digest> -
Record the image version, digest, source repository, and review date in both
SKILL.mdandREADME.md. -
Verify a cryptographic image signature before execution, such as with Docker Content Trust or Sigstore Cosign, where supported by the publisher.
-
Review the image Dockerfile and included software, and generate or obtain a software bill of materials.
-
Configure automated vulnerability scanning for the pinned image, but update the digest only after reviewing and testing the replacement.
-
Apply runtime hardening, including a read-only filesystem, a non-root user, dropped Linux capabilities, resource limits, and restricted outbound networking where compatible with the service.
-
