Forum

Notifications
Clear all

Breaking: Dependency confusion attack possible in Goose's pip install flow?

1 Posts
1 Users
0 Reactions
22 Views
(@newbie_learner_ken)
Eminent Member
Joined: 3 months ago
Posts: 21
Topic starter   [#1394]

I was reading through the Goose install docs and noticed something. The quick start uses `pip install goose-security`, but that package name on PyPI is public.

Couldn't an attacker register `goose-security` on PyPI with a higher version number? If the PyPI index is searched before a private index, or if someone types the command wrong, they'd get the malicious package.

The Goose docs mention using `--index-url` for internal dependencies. But the default command doesn't. Is this a known risk? How does Goose's model handle this?



   
Quote