Togoder security

Go package security report

github.com/Masterminds/sprig/v3 Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v3.3.0 Files reviewed 14 Size 59.7 KB Scanned

Summary

Togoder Security scanned the Go package github.com/Masterminds/sprig/v3@v3.3.0 on Oct 5, 2026. An AI review of 14 source files produced 7 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
7
medium
8
low

Findings 15

medium

Weak cryptography

NPS-855AE54B97B8

The encryptAES function uses AES-CBC with a key derived by simply copying the password bytes into a 32-byte buffer (zero-padded if shorter). This lacks proper key derivation (e.g., PBKDF2, scrypt) and uses PKCS#7 padding, making it vulnerable to padding oracle attacks. Additionally, CBC mode without authentication (e.g., HMAC) is susceptible to bit-flipping attacks.

crypto.go:575
medium

Weak cryptography

NPS-3A7B4B4FC91E

The decryptAES function performs AES-CBC decryption without verifying integrity or padding correctly (it simply slices off the last byte as padding length without validation), which can lead to panics or padding oracle vulnerabilities.

crypto.go:609
medium

Environment variable access

NPS-1B6A4636897A

The function map includes 'env' and 'expandenv' which directly call os.Getenv and os.ExpandEnv. This allows template authors to read arbitrary environment variables, which may contain sensitive data such as API keys, tokens, or credentials. While this is a documented feature of the sprig library, it poses a security risk if templates are not fully trusted.

functions.go:287
medium

Ignored error handling

NPS-41E8CAC940D6

The error returned by net.LookupHost is discarded. If DNS resolution fails (e.g., no such host, network issues), addrs will be nil or empty, causing rand.Intn(0) to panic with 'invalid argument to Intn'. This is a reliability/availability bug rather than a direct security exploit, but can be triggered by invalid input passed to the template function.

network.go:9
medium

Potential panic via attacker-controlled input

NPS-8DD889A60170

getHostByName accepts an arbitrary name string and passes it directly to net.LookupHost. A caller (e.g., a template author) supplying a name that fails to resolve will cause a panic on rand.Intn(len(addrs)) since len(addrs)==0, potentially crashing the process if panics are not recovered.

network.go:10
medium

Resource exhaustion / ReDoS risk

NPS-CA319999E960

Regexes are compiled on every call to regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit via regexp.MustCompile. An attacker-supplied regex can trigger a panic (unrecovered MustCompile on invalid pattern) or cause a denial-of-service via catastrophic backtracking / excessive compilation, since there is no caching or validation. The 'must' variants return errors, but the non-must variants will panic on invalid input.

regex.go:14
medium

Panic-based denial of service

NPS-C8EA60D597B6

Functions regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit call regexp.MustCompile with user-controlled input. A malformed regex will cause a runtime panic, crashing the process or template rendering engine (sprig is commonly used in Helm templates). This is a reliability/DoS concern rather than overt malware.

regex.go:38
low

Weak cryptographic hash

NPS-F4D74F5D55A4

The sha1sum function uses SHA-1, which is cryptographically broken and should not be used for security-sensitive purposes.

crypto.go:32
low

Weak cryptographic hash

NPS-CD3E6185C197

The adler32sum function uses Adler-32, which is not a cryptographic hash and provides no security guarantees.

crypto.go:37
low

Predictable randomness

NPS-F01421B8D252

The derivePassword function uses a deterministic counter-based approach with HMAC-SHA256 for password generation, which is intended but relies on scrypt with a fixed salt derived from user input. This is by design for Master Password algorithm, but the use of a weak salt (length-prefixed user) could be a concern if the password is weak.

crypto.go:103
low

Potential key exposure

NPS-7D88F5789A27

The generatePrivateKey function returns private keys as PEM-encoded strings, which could be logged or exposed if not handled carefully. This is a common utility but requires caution.

crypto.go:148
low

Insecure certificate generation

NPS-48D5263C1198

The certificate generation functions (generateCertificateAuthority, generateSelfSignedCertificate, generateSignedCertificate) use RSA 2048-bit keys, which is acceptable but could be stronger. They also set BasicConstraintsValid to true without properly setting IsCA for non-CA certificates, which might lead to misconfigurations.

crypto.go:477
low

Non-hermetic functions explicitly listed

NPS-E7E28EB56EB5

The code explicitly identifies non-hermetic functions (those that depend on environment, time, or randomness) and provides hermetic variants that exclude them. This is good security practice, but the presence of the non-hermetic functions in the default map remains a potential risk.

functions.go:59
low

Network-related function

NPS-72A5376CD3B0

The function map includes 'getHostByName' which performs DNS lookups. This can be used for data exfiltration or network reconnaissance from within a template context.

functions.go:289
low

Cryptographic operations

NPS-ACBFECDFB2C4

The function map exposes numerous cryptographic functions including bcrypt, htpasswd, key generation, certificate generation, and AES encryption/decryption. While not inherently malicious, these could be misused to generate keys, encrypt data, or create certificates within a template context.

functions.go:345

Files reviewed

FileVerdictWhat the reviewer saw
crypto.go medium The code contains several cryptographic weaknesses (insecure AES-CBC usage, weak hashes) but no malicious patterns such as data exfiltration or backdoors.
functions.go medium The sprig library exposes environment variable access, DNS lookups, and cryptographic functions through its template function map, which could be exploited if untrusted templates are used, but no overtly malicious code was found.
network.go medium No malicious code or exfiltration was found, but the function has an unhandled error path that can panic on unresolvable hostnames, posing a minor availability risk.
regex.go medium No malicious exfiltration, network, filesystem, or code-execution patterns found; the only concerns are potential denial-of-service/panic issues from user-controlled regex compilation.
date.go safe Cleared by Jev triage; no further analysis needed
defaults.go safe No malicious patterns detected; the file contains standard template helper functions from the sprig library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior beyond a benign random seed in init().
dict.go safe No malicious patterns detected; this is a standard Go template utility library with map manipulation functions.
doc.go safe Cleared by Jev triage; no further analysis needed
list.go safe Cleared by Jev triage; no further analysis needed
numeric.go safe Cleared by Jev triage; no further analysis needed
reflect.go safe Cleared by Jev triage; no further analysis needed
semver.go safe Cleared by Jev triage; no further analysis needed
strings.go safe Cleared by Jev triage; no further analysis needed
url.go safe No malicious patterns detected; the code only provides URL parsing and joining functionality typical of the sprig template library.

Scanned versions of github.com/Masterminds/sprig/v3

VersionVerdictFilesScanned
v3.3.0 Needs review 14 Oct 5, 2026

Frequently asked questions

Is github.com/Masterminds/sprig/v3 safe to use?

No confirmed malware was found in github.com/Masterminds/sprig/v3@v3.3.0, but the review flagged 7 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/Masterminds/sprig/v3 contain malware?

No malware was identified in github.com/Masterminds/sprig/v3@v3.3.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/Masterminds/sprig/v3 checked?

Togoder Security downloaded the published Go package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/Masterminds/sprig/v3 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/Masterminds/sprig/v3@v3.3.0, cost nothing.

Related security reports