Remote code download without integrity verification

Remote code download without integrity verification

Description

Storing or executing downloaded scripts or plugins without verifying a hash, signature, or fixed trust chain may run modified code with the application's permissions.

Potential impact

  • Network tampering or repository compromise may introduce malicious code.
  • Persistent backdoors or arbitrary files may be installed in the deployment environment.

Remediation

  • Verify the downloaded code's SHA-256 digest or digital signature.
  • Prefer package managers, lockfiles, and signature verification over downloading code at runtime where possible.

Examples

Before

python
code = requests.get(url).text
exec(code)

After

python
data = requests.get(url, timeout=5).content
digest = hashlib.sha256(data).hexdigest()
if not hmac.compare_digest(digest, expected_digest):
    raise ValueError("bad digest")

Explanation:

  • Before: Downloaded scripts or plugins are executed without a verified hash, signature, or fixed trust chain. Network tampering, repository compromise, or DNS manipulation can introduce malicious code.
  • After: The downloaded code's SHA-256 digest or signature is checked against a fixed, trusted value.

References