Summary
Togoder Security scanned the Go package github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible on Oct 5, 2026. An AI review of 25 source files produced 4 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 13
SQL Injection via Table Name
NPS-3EE0E5ED59DE
All dialect methods construct SQL by directly interpolating TableName() into SQL strings via fmt.Sprintf, without quoting or escaping. If an application sets a custom table name from untrusted input, this enables SQL injection. This is a latent vulnerability in a widely used migration library (goose).
SQL Injection via Table Name (repeated)
NPS-633FAEA158F6
The same TableName() interpolation pattern is repeated across every dialect's createVersionTableSQL, insertVersionSQL, dbVersionQuery, migrationSQL, and deleteVersionSQL methods (Postgres, MySQL, MSSQL, SQLite3, Redshift, TiDB). Any dialect selected by SetDialect inherits this pattern.
Improper error handling
NPS-4F9E8FFA3026
In dbMigrationsStatus, when GetDialect().dbVersionQuery(db) returns an error, the function returns an empty map and nil error instead of propagating the error. This could mask database connection or query failures, leading to unintended behavior such as skipping rollback operations silently.
Potential destructive operation without error propagation
NPS-D2D8DB206C3B
The Reset function rolls back all migrations. If dbMigrationsStatus fails to retrieve statuses correctly (due to the swallowed error above), it may proceed with an empty status map and fail to roll back any migrations, or in other scenarios could incorrectly roll back. This is a logic flaw that could leave the database in an inconsistent state.
Global Mutable Dialect State
NPS-51ECCFDDD10D
SetDialect mutates a package-level variable (dialect) with no synchronization. Concurrent callers could race and cause inconsistent behavior, and any code in the process can silently swap the dialect. This is a design/thread-safety concern rather than a direct exploit.
File system manipulation
NPS-0013BC56912B
The code renames files using os.Rename, which could modify files outside the intended migration directory if the newPath is constructed in a way that escapes the directory (e.g., via path traversal). However, the newPath is derived from oldPath by replacing the version number with a formatted version, and the oldPath comes from CollectMigrations which presumably lists files within dir. This is likely intended functionality for fixing migration filenames, but could be risky if dir is user-controlled or if symlinks are present.
Potential path traversal
NPS-DC8597A95887
The newPath is built using strings.Replace on the oldPath, which includes the directory. If the version number appears in the directory portion, it could inadvertently rename the directory or cause unexpected path changes. Additionally, if the migration version is negative or has unusual formatting, the replacement might not match, but the code would still attempt to rename. This is not malicious per se, but could lead to unintended file operations.
Deprecated unsafe package
NPS-1BCA2D5B8350
Import of 'github.com/pkg/errors' which is deprecated and no longer maintained. While not malicious, using deprecated packages introduces security risks as vulnerabilities may not be patched.
Unsafe error formatting
NPS-50B70FAF30EB
The String() method uses fmt.Sprintf(m.Source) where m.Source is used directly as the format string. If m.Source contains format specifiers (e.g., %s, %n, %v), this could lead to unexpected behavior or potentially leak panic information. In Go, this is flagged by go vet as a potential bug. While not directly malicious, it's poor practice and could be exploited if migration source paths are attacker-controlled.
Potential path traversal / information disclosure
NPS-3AB41AD2B0F5
The code uses strings.Split(m.Source, 'migrations') and accesses x[1][1:] without bounds checking. If m.Source does not contain 'migrations', this will cause a panic (index out of range). Similarly, in NumericComponent, strings.Split(name, 'migrations') followed by accessing versionFolder[1][1:] could panic. This is a robustness issue that could be triggered by an attacker supplying a crafted migration path, potentially causing denial of service.
Memory allocation from sync.Pool
NPS-849B31A68ECE
The code uses sync.Pool to reuse a 4MB buffer for scanning. This is standard for performance; no malicious intent.
Regular expression match on empty lines
NPS-2D3B7D839126
The regex ^\s*$ is used to skip empty lines; no security impact.
Logging of migration content
NPS-56E015EFC23D
When verbose mode is enabled, the parser logs SQL lines. This could leak sensitive SQL content if verbose logging is enabled in an insecure environment, but it is intentional for debugging and not a malicious pattern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dialect.go | medium | The file contains no malicious behaviors (no exfiltration, credential harvesting, obfuscation, mining, backdoors, or process execution), but it exhibits a latent SQL-injection pattern via unquoted TableName() interpolation that could be exploitable in downstream applications. |
| fix.go | medium | The code performs file renaming operations within the migration directory, which is likely legitimate but could pose a low risk if input paths are not properly validated. |
| migration.go | medium | No malicious patterns detected; code is a legitimate database migration library (goose) with minor code quality issues. |
| reset.go | medium | The code contains no malicious patterns but has error handling flaws that could lead to unintended database state during migration rollback. |
| cmd/goose/driver_mssql.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/goose/driver_mysql.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/goose/driver_no_mysql.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/goose/driver_postgres.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/goose/driver_sqlite3.go | safe | No malicious patterns detected; this file only imports the go-sqlite3 driver via a blank import for side effects. |
| cmd/goose/main.go | safe | No malicious patterns detected; the file is a straightforward CLI entry point for the goose database migration tool. |
| create.go | safe | No malicious patterns detected; the code generates local Go migration files using standard library calls without any network, credential, or process execution activity. |
| db.go | safe | No malicious patterns detected |
| down.go | safe | Cleared by Jev triage; no further analysis needed |
| examples/go-migrations/00002_rename_root.go | safe | No malicious patterns detected; the code is a standard database migration for renaming a username and does not exhibit any security concerns. |
| examples/go-migrations/main.go | safe | No malicious patterns detected |
| goose.go | safe | No malicious patterns detected in the analyzed Go source file; it is a benign database migration tool with standard command dispatch logic. |
| helpers.go | safe | No malicious patterns detected; the code is a benign string case conversion utility. |
| log.go | safe | No malicious patterns detected |
| migrate.go | safe | No malicious patterns detected; the code is a standard database migration library with no external network, credential, or exec operations. |
| migration_sql.go | safe | No malicious patterns detected; the code is a legitimate database migration utility for the goose library. |
| redo.go | safe | Cleared by Jev triage; no further analysis needed |
| sql_parser.go | safe | The code is a benign SQL migration parser with no malicious patterns; it only processes input from an io.Reader and does not perform network, filesystem, or process operations. |
| status.go | safe | No malicious patterns detected |
| up.go | safe | The code is a standard database migration library (goose) with no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| version.go | safe | No malicious patterns detected |
Frequently asked questions
Is github.com/thrasher-corp/goose safe to use?
No confirmed malware was found in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible, but the review flagged 4 medium, 9 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/thrasher-corp/goose contain malware?
No malware was identified in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/thrasher-corp/goose checked?
Togoder Security downloaded the published Go package and had an AI model read its 25 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/thrasher-corp/goose together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/goose@v2.7.0-rc4.0.20191002032028-0f2c2a27abdb+incompatible, cost nothing.