# github.com/pelletier/go-toml/v2@v2.2.4 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:36.000Z
- Files reviewed: 36
- Findings: 2 high, 2 medium severity findings
- Report: https://security.togoder.click/go/github.com/pelletier/go-toml/v2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/pelletier/go-toml/v2@v2.2.4 on Oct 5, 2026. An AI review of 36 source files produced 2 high, 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Unsafe memory manipulation

Finding ID: `NPS-79D8AF339620`

File: `internal/danger/danger.go:1`

The code uses the unsafe package to bypass Go's memory safety guarantees, directly manipulating slice headers and performing pointer arithmetic. This can lead to memory corruption, crashes, or arbitrary memory read/write if the inputs are not strictly controlled.

### [high] Potential for invalid pointer arithmetic

Finding ID: `NPS-FB20493EFC67`

File: `internal/danger/danger.go:79`

The Stride function performs unchecked pointer arithmetic using unsafe.Pointer and uintptr. If the offset or size values are attacker-controlled, this can result in out-of-bounds memory access, potentially leading to exploitation.

### [medium] Missing input validation

Finding ID: `NPS-F6EED346AE7F`

File: `internal/danger/danger.go:61`

Functions like SubsliceOffset and BytesRange perform validation, but the reliance on unsafe operations means that any bypass or incorrect use could lead to memory safety issues. The code does not prevent the creation of out-of-bounds slices if the checks are circumvented (e.g., via integer overflows in endLen calculation in BytesRange).

### [medium] Unsafe pointer manipulation

Finding ID: `NPS-27CB276C2966`

File: `internal/danger/typeid.go:20`

The code uses unsafe.Pointer and type punning to extract an internal pointer from a reflect.Type value by casting it to a [2]unsafe.Pointer array and taking the second element. This relies on undocumented internal layout of reflect.Type (which is a non-empty interface). While this is a known pattern used in performance-sensitive code (and attributed to segmentio/encoding), it is inherently fragile, undefined behavior, and could break or cause memory corruption in future Go versions or different runtimes. It is not directly malicious, but indicates unsafe low-level memory access.

## Files reviewed

- `internal/danger/danger.go` (medium): The code uses unsafe memory operations and pointer arithmetic, which, while possibly intended for performance or low-level functionality, pose significant security risks if not used with extreme care.
- `internal/danger/typeid.go` (medium): The file contains no malicious patterns (no exfiltration, credential harvesting, obfuscation, network/process/file access), but uses unsafe pointer tricks to extract internal reflect.Type data, which is a risky and fragile low-level operation.
- `cmd/gotoml-test-decoder/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/gotoml-test-encoder/gotoml-test-encoder.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/jsontoml/main.go` (safe): No malicious patterns detected; the code is a simple JSON-to-TOML converter using standard library and internal package functions without network, filesystem, process execution, or credential access.
- `cmd/tomljson/main.go` (safe): The TOML-to-JSON converter contains no malicious patterns; it performs straightforward parsing and encoding with no external calls, credential access, or code execution features.
- `cmd/tomll/main.go` (safe): No malicious patterns detected
- `cmd/tomltestgen/main.go` (safe): This code is a legitimate test generator that reads local TOML test files and produces Go test source code; it contains no network access, credential harvesting, dynamic code execution, or other malicious patterns.
- `decode.go` (safe): Cleared by Jev triage; no further analysis needed
- `doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/assert/assertions.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/characters/ascii.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/characters/utf8.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cli/cli.go` (safe): No malicious patterns detected; the code is a straightforward CLI wrapper for TOML conversion with standard file I/O and no external network or process execution.
- `internal/testsuite/add.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testsuite/json.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testsuite/parser.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testsuite/rm.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testsuite/testsuite.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/tracker/key.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/tracker/seen.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/tracker/tracker.go` (safe): Cleared by Jev triage; no further analysis needed
- `localtime.go` (safe): Cleared by Jev triage; no further analysis needed
- `marshaler.go` (safe): Cleared by Jev triage; no further analysis needed
- `ossfuzz/fuzz.go` (safe): No malicious patterns detected
- `strict.go` (safe): Cleared by Jev triage; no further analysis needed
- `types.go` (safe): Cleared by Jev triage; no further analysis needed
- `unmarshaler.go` (safe): No malicious patterns detected; this is the standard go-toml v2 unmarshaler with legitimate reflection-based TOML decoding logic and no data exfiltration, obfuscation, or process spawning.
- `unstable/ast.go` (safe): No malicious patterns detected; the file contains only safe AST iterator logic for TOML parsing with well-scoped unsafe pointer arithmetic.
- `unstable/builder.go` (safe): Cleared by Jev triage; no further analysis needed
- `unstable/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `unstable/kind.go` (safe): Cleared by Jev triage; no further analysis needed
- `unstable/parser.go` (safe): Cleared by Jev triage; no further analysis needed
- `unstable/scanner.go` (safe): Cleared by Jev triage; no further analysis needed
- `unstable/unmarshaler.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
