Summary
Togoder Security scanned the Go package github.com/Masterminds/sprig/v3@v3.3.0 on Oct 5, 2026. An AI review of 14 source files produced 7 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 15
Weak cryptography
NPS-855AE54B97B8
The encryptAES function uses AES-CBC with a key derived by simply copying the password bytes into a 32-byte buffer (zero-padded if shorter). This lacks proper key derivation (e.g., PBKDF2, scrypt) and uses PKCS#7 padding, making it vulnerable to padding oracle attacks. Additionally, CBC mode without authentication (e.g., HMAC) is susceptible to bit-flipping attacks.
Weak cryptography
NPS-3A7B4B4FC91E
The decryptAES function performs AES-CBC decryption without verifying integrity or padding correctly (it simply slices off the last byte as padding length without validation), which can lead to panics or padding oracle vulnerabilities.
Environment variable access
NPS-1B6A4636897A
The function map includes 'env' and 'expandenv' which directly call os.Getenv and os.ExpandEnv. This allows template authors to read arbitrary environment variables, which may contain sensitive data such as API keys, tokens, or credentials. While this is a documented feature of the sprig library, it poses a security risk if templates are not fully trusted.
Ignored error handling
NPS-41E8CAC940D6
The error returned by net.LookupHost is discarded. If DNS resolution fails (e.g., no such host, network issues), addrs will be nil or empty, causing rand.Intn(0) to panic with 'invalid argument to Intn'. This is a reliability/availability bug rather than a direct security exploit, but can be triggered by invalid input passed to the template function.
Potential panic via attacker-controlled input
NPS-8DD889A60170
getHostByName accepts an arbitrary name string and passes it directly to net.LookupHost. A caller (e.g., a template author) supplying a name that fails to resolve will cause a panic on rand.Intn(len(addrs)) since len(addrs)==0, potentially crashing the process if panics are not recovered.
Resource exhaustion / ReDoS risk
NPS-CA319999E960
Regexes are compiled on every call to regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit via regexp.MustCompile. An attacker-supplied regex can trigger a panic (unrecovered MustCompile on invalid pattern) or cause a denial-of-service via catastrophic backtracking / excessive compilation, since there is no caching or validation. The 'must' variants return errors, but the non-must variants will panic on invalid input.
Panic-based denial of service
NPS-C8EA60D597B6
Functions regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit call regexp.MustCompile with user-controlled input. A malformed regex will cause a runtime panic, crashing the process or template rendering engine (sprig is commonly used in Helm templates). This is a reliability/DoS concern rather than overt malware.
Weak cryptographic hash
NPS-F4D74F5D55A4
The sha1sum function uses SHA-1, which is cryptographically broken and should not be used for security-sensitive purposes.
Weak cryptographic hash
NPS-CD3E6185C197
The adler32sum function uses Adler-32, which is not a cryptographic hash and provides no security guarantees.
Predictable randomness
NPS-F01421B8D252
The derivePassword function uses a deterministic counter-based approach with HMAC-SHA256 for password generation, which is intended but relies on scrypt with a fixed salt derived from user input. This is by design for Master Password algorithm, but the use of a weak salt (length-prefixed user) could be a concern if the password is weak.
Potential key exposure
NPS-7D88F5789A27
The generatePrivateKey function returns private keys as PEM-encoded strings, which could be logged or exposed if not handled carefully. This is a common utility but requires caution.
Insecure certificate generation
NPS-48D5263C1198
The certificate generation functions (generateCertificateAuthority, generateSelfSignedCertificate, generateSignedCertificate) use RSA 2048-bit keys, which is acceptable but could be stronger. They also set BasicConstraintsValid to true without properly setting IsCA for non-CA certificates, which might lead to misconfigurations.
Non-hermetic functions explicitly listed
NPS-E7E28EB56EB5
The code explicitly identifies non-hermetic functions (those that depend on environment, time, or randomness) and provides hermetic variants that exclude them. This is good security practice, but the presence of the non-hermetic functions in the default map remains a potential risk.
Network-related function
NPS-72A5376CD3B0
The function map includes 'getHostByName' which performs DNS lookups. This can be used for data exfiltration or network reconnaissance from within a template context.
Cryptographic operations
NPS-ACBFECDFB2C4
The function map exposes numerous cryptographic functions including bcrypt, htpasswd, key generation, certificate generation, and AES encryption/decryption. While not inherently malicious, these could be misused to generate keys, encrypt data, or create certificates within a template context.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| crypto.go | medium | The code contains several cryptographic weaknesses (insecure AES-CBC usage, weak hashes) but no malicious patterns such as data exfiltration or backdoors. |
| functions.go | medium | The sprig library exposes environment variable access, DNS lookups, and cryptographic functions through its template function map, which could be exploited if untrusted templates are used, but no overtly malicious code was found. |
| network.go | medium | No malicious code or exfiltration was found, but the function has an unhandled error path that can panic on unresolvable hostnames, posing a minor availability risk. |
| regex.go | medium | No malicious exfiltration, network, filesystem, or code-execution patterns found; the only concerns are potential denial-of-service/panic issues from user-controlled regex compilation. |
| date.go | safe | Cleared by Jev triage; no further analysis needed |
| defaults.go | safe | No malicious patterns detected; the file contains standard template helper functions from the sprig library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior beyond a benign random seed in init(). |
| dict.go | safe | No malicious patterns detected; this is a standard Go template utility library with map manipulation functions. |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| list.go | safe | Cleared by Jev triage; no further analysis needed |
| numeric.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect.go | safe | Cleared by Jev triage; no further analysis needed |
| semver.go | safe | Cleared by Jev triage; no further analysis needed |
| strings.go | safe | Cleared by Jev triage; no further analysis needed |
| url.go | safe | No malicious patterns detected; the code only provides URL parsing and joining functionality typical of the sprig template library. |
Scanned versions of github.com/Masterminds/sprig/v3
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v3.3.0 | Needs review | 14 | Oct 5, 2026 |
Frequently asked questions
Is github.com/Masterminds/sprig/v3 safe to use?
No confirmed malware was found in github.com/Masterminds/sprig/v3@v3.3.0, but the review flagged 7 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/Masterminds/sprig/v3 contain malware?
No malware was identified in github.com/Masterminds/sprig/v3@v3.3.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/Masterminds/sprig/v3 checked?
Togoder Security downloaded the published Go package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/Masterminds/sprig/v3 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/Masterminds/sprig/v3@v3.3.0, cost nothing.