Summary
Togoder Security scanned the Go package github.com/pelletier/go-toml/v2@v2.2.4 on Oct 5, 2026. An AI review of 36 source files produced 2 high, 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Unsafe memory manipulation
NPS-79D8AF339620
The code uses the unsafe package to bypass Go's memory safety guarantees, directly manipulating slice headers and performing pointer arithmetic. This can lead to memory corruption, crashes, or arbitrary memory read/write if the inputs are not strictly controlled.
Potential for invalid pointer arithmetic
NPS-FB20493EFC67
The Stride function performs unchecked pointer arithmetic using unsafe.Pointer and uintptr. If the offset or size values are attacker-controlled, this can result in out-of-bounds memory access, potentially leading to exploitation.
Missing input validation
NPS-F6EED346AE7F
Functions like SubsliceOffset and BytesRange perform validation, but the reliance on unsafe operations means that any bypass or incorrect use could lead to memory safety issues. The code does not prevent the creation of out-of-bounds slices if the checks are circumvented (e.g., via integer overflows in endLen calculation in BytesRange).
Unsafe pointer manipulation
NPS-27CB276C2966
The code uses unsafe.Pointer and type punning to extract an internal pointer from a reflect.Type value by casting it to a [2]unsafe.Pointer array and taking the second element. This relies on undocumented internal layout of reflect.Type (which is a non-empty interface). While this is a known pattern used in performance-sensitive code (and attributed to segmentio/encoding), it is inherently fragile, undefined behavior, and could break or cause memory corruption in future Go versions or different runtimes. It is not directly malicious, but indicates unsafe low-level memory access.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/danger/danger.go | medium | The code uses unsafe memory operations and pointer arithmetic, which, while possibly intended for performance or low-level functionality, pose significant security risks if not used with extreme care. |
| internal/danger/typeid.go | medium | The file contains no malicious patterns (no exfiltration, credential harvesting, obfuscation, network/process/file access), but uses unsafe pointer tricks to extract internal reflect.Type data, which is a risky and fragile low-level operation. |
| cmd/gotoml-test-decoder/main.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/gotoml-test-encoder/gotoml-test-encoder.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/jsontoml/main.go | safe | No malicious patterns detected; the code is a simple JSON-to-TOML converter using standard library and internal package functions without network, filesystem, process execution, or credential access. |
| cmd/tomljson/main.go | safe | The TOML-to-JSON converter contains no malicious patterns; it performs straightforward parsing and encoding with no external calls, credential access, or code execution features. |
| cmd/tomll/main.go | safe | No malicious patterns detected |
| cmd/tomltestgen/main.go | safe | This code is a legitimate test generator that reads local TOML test files and produces Go test source code; it contains no network access, credential harvesting, dynamic code execution, or other malicious patterns. |
| decode.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| errors.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/assert/assertions.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/characters/ascii.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/characters/utf8.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cli/cli.go | safe | No malicious patterns detected; the code is a straightforward CLI wrapper for TOML conversion with standard file I/O and no external network or process execution. |
| internal/testsuite/add.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testsuite/json.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testsuite/parser.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testsuite/rm.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testsuite/testsuite.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/tracker/key.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/tracker/seen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/tracker/tracker.go | safe | Cleared by Jev triage; no further analysis needed |
| localtime.go | safe | Cleared by Jev triage; no further analysis needed |
| marshaler.go | safe | Cleared by Jev triage; no further analysis needed |
Show 11 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| ossfuzz/fuzz.go | safe | No malicious patterns detected |
| strict.go | safe | Cleared by Jev triage; no further analysis needed |
| types.go | safe | Cleared by Jev triage; no further analysis needed |
| unmarshaler.go | safe | No malicious patterns detected; this is the standard go-toml v2 unmarshaler with legitimate reflection-based TOML decoding logic and no data exfiltration, obfuscation, or process spawning. |
| unstable/ast.go | safe | No malicious patterns detected; the file contains only safe AST iterator logic for TOML parsing with well-scoped unsafe pointer arithmetic. |
| unstable/builder.go | safe | Cleared by Jev triage; no further analysis needed |
| unstable/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| unstable/kind.go | safe | Cleared by Jev triage; no further analysis needed |
| unstable/parser.go | safe | Cleared by Jev triage; no further analysis needed |
| unstable/scanner.go | safe | Cleared by Jev triage; no further analysis needed |
| unstable/unmarshaler.go | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of github.com/pelletier/go-toml/v2
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v2.2.4 | Needs review | 36 | Oct 5, 2026 |
Frequently asked questions
Is github.com/pelletier/go-toml/v2 safe to use?
No confirmed malware was found in github.com/pelletier/go-toml/v2@v2.2.4, but the review flagged 2 high, 2 medium severity findings for risky patterns worth checking before you rely on it.
Does github.com/pelletier/go-toml/v2 contain malware?
No malware was identified in github.com/pelletier/go-toml/v2@v2.2.4 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/pelletier/go-toml/v2 checked?
Togoder Security downloaded the published Go package and had an AI model read its 36 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/pelletier/go-toml/v2 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/pelletier/go-toml/v2@v2.2.4, cost nothing.