Togoder security

Go package security report

github.com/pelletier/go-toml/v2 Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v2.2.4 Files reviewed 36 Size 165.9 KB Scanned

Summary

Togoder Security scanned the Go package github.com/pelletier/go-toml/v2@v2.2.4 on Oct 5, 2026. An AI review of 36 source files produced 2 high, 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
2
high
2
medium
0
low

Findings 4

high

Unsafe memory manipulation

NPS-79D8AF339620

The code uses the unsafe package to bypass Go's memory safety guarantees, directly manipulating slice headers and performing pointer arithmetic. This can lead to memory corruption, crashes, or arbitrary memory read/write if the inputs are not strictly controlled.

internal/danger/danger.go:1
high

Potential for invalid pointer arithmetic

NPS-FB20493EFC67

The Stride function performs unchecked pointer arithmetic using unsafe.Pointer and uintptr. If the offset or size values are attacker-controlled, this can result in out-of-bounds memory access, potentially leading to exploitation.

internal/danger/danger.go:79
medium

Missing input validation

NPS-F6EED346AE7F

Functions like SubsliceOffset and BytesRange perform validation, but the reliance on unsafe operations means that any bypass or incorrect use could lead to memory safety issues. The code does not prevent the creation of out-of-bounds slices if the checks are circumvented (e.g., via integer overflows in endLen calculation in BytesRange).

internal/danger/danger.go:61
medium

Unsafe pointer manipulation

NPS-27CB276C2966

The code uses unsafe.Pointer and type punning to extract an internal pointer from a reflect.Type value by casting it to a [2]unsafe.Pointer array and taking the second element. This relies on undocumented internal layout of reflect.Type (which is a non-empty interface). While this is a known pattern used in performance-sensitive code (and attributed to segmentio/encoding), it is inherently fragile, undefined behavior, and could break or cause memory corruption in future Go versions or different runtimes. It is not directly malicious, but indicates unsafe low-level memory access.

internal/danger/typeid.go:20

Files reviewed

FileVerdictWhat the reviewer saw
internal/danger/danger.go medium The code uses unsafe memory operations and pointer arithmetic, which, while possibly intended for performance or low-level functionality, pose significant security risks if not used with extreme care.
internal/danger/typeid.go medium The file contains no malicious patterns (no exfiltration, credential harvesting, obfuscation, network/process/file access), but uses unsafe pointer tricks to extract internal reflect.Type data, which is a risky and fragile low-level operation.
cmd/gotoml-test-decoder/main.go safe Cleared by Jev triage; no further analysis needed
cmd/gotoml-test-encoder/gotoml-test-encoder.go safe Cleared by Jev triage; no further analysis needed
cmd/jsontoml/main.go safe No malicious patterns detected; the code is a simple JSON-to-TOML converter using standard library and internal package functions without network, filesystem, process execution, or credential access.
cmd/tomljson/main.go safe The TOML-to-JSON converter contains no malicious patterns; it performs straightforward parsing and encoding with no external calls, credential access, or code execution features.
cmd/tomll/main.go safe No malicious patterns detected
cmd/tomltestgen/main.go safe This code is a legitimate test generator that reads local TOML test files and produces Go test source code; it contains no network access, credential harvesting, dynamic code execution, or other malicious patterns.
decode.go safe Cleared by Jev triage; no further analysis needed
doc.go safe Cleared by Jev triage; no further analysis needed
errors.go safe Cleared by Jev triage; no further analysis needed
internal/assert/assertions.go safe Cleared by Jev triage; no further analysis needed
internal/characters/ascii.go safe Cleared by Jev triage; no further analysis needed
internal/characters/utf8.go safe Cleared by Jev triage; no further analysis needed
internal/cli/cli.go safe No malicious patterns detected; the code is a straightforward CLI wrapper for TOML conversion with standard file I/O and no external network or process execution.
internal/testsuite/add.go safe Cleared by Jev triage; no further analysis needed
internal/testsuite/json.go safe Cleared by Jev triage; no further analysis needed
internal/testsuite/parser.go safe Cleared by Jev triage; no further analysis needed
internal/testsuite/rm.go safe Cleared by Jev triage; no further analysis needed
internal/testsuite/testsuite.go safe Cleared by Jev triage; no further analysis needed
internal/tracker/key.go safe Cleared by Jev triage; no further analysis needed
internal/tracker/seen.go safe Cleared by Jev triage; no further analysis needed
internal/tracker/tracker.go safe Cleared by Jev triage; no further analysis needed
localtime.go safe Cleared by Jev triage; no further analysis needed
marshaler.go safe Cleared by Jev triage; no further analysis needed
Show 11 more files
FileVerdictWhat the reviewer saw
ossfuzz/fuzz.go safe No malicious patterns detected
strict.go safe Cleared by Jev triage; no further analysis needed
types.go safe Cleared by Jev triage; no further analysis needed
unmarshaler.go safe No malicious patterns detected; this is the standard go-toml v2 unmarshaler with legitimate reflection-based TOML decoding logic and no data exfiltration, obfuscation, or process spawning.
unstable/ast.go safe No malicious patterns detected; the file contains only safe AST iterator logic for TOML parsing with well-scoped unsafe pointer arithmetic.
unstable/builder.go safe Cleared by Jev triage; no further analysis needed
unstable/doc.go safe Cleared by Jev triage; no further analysis needed
unstable/kind.go safe Cleared by Jev triage; no further analysis needed
unstable/parser.go safe Cleared by Jev triage; no further analysis needed
unstable/scanner.go safe Cleared by Jev triage; no further analysis needed
unstable/unmarshaler.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/pelletier/go-toml/v2

VersionVerdictFilesScanned
v2.2.4 Needs review 36 Oct 5, 2026

Frequently asked questions

Is github.com/pelletier/go-toml/v2 safe to use?

No confirmed malware was found in github.com/pelletier/go-toml/v2@v2.2.4, but the review flagged 2 high, 2 medium severity findings for risky patterns worth checking before you rely on it.

Does github.com/pelletier/go-toml/v2 contain malware?

No malware was identified in github.com/pelletier/go-toml/v2@v2.2.4 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/pelletier/go-toml/v2 checked?

Togoder Security downloaded the published Go package and had an AI model read its 36 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/pelletier/go-toml/v2 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/pelletier/go-toml/v2@v2.2.4, cost nothing.

Related security reports