# github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:10.000Z
- Files reviewed: 66
- Findings: 5 medium, 12 low severity findings
- Report: https://security.togoder.click/go/github.com/thrasher-corp/sqlboiler
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e on Oct 5, 2026. An AI review of 66 source files produced 5 medium, 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic execution of external binaries

Finding ID: `NPS-3ABD5F4C7B93`

File: `drivers/binary_driver.go:52`

The execute function calls external binaries with arguments ('assemble', 'templates', 'imports') and passes JSON input via stdin. While this is the intended functionality of the driver, it relies on trust in the external binary. Malicious or compromised binaries could perform arbitrary actions, including data exfiltration, since they receive configuration data and run with the same privileges as the calling process.

### [medium] Spawning processes or shell commands

Finding ID: `NPS-213CB3D9C13B`

File: `drivers/binary_driver.go:64`

The code uses os/exec to spawn external binaries based on the binaryDriver string. The executable path comes from the driver configuration and is passed directly to exec.Command without validation or sanitization. If an attacker can control the driver name (e.g., through configuration), they could execute arbitrary binaries on the system. This is a potential command execution vector.

### [medium] Potential connection string injection / improper escaping

Finding ID: `NPS-F9CE45EE6D39`

File: `drivers/sqlboiler-psql/driver/psql.go:113`

PSQLBuildQueryString constructs a PostgreSQL connection string by directly interpolating user, password, dbname, host, and sslmode values with fmt.Sprintf without proper escaping. If any of these values contain spaces or special characters (e.g. a password with a space, or a host value containing ' sslmode=disable'), it could allow an attacker who controls config values to inject additional connection parameters, potentially weakening TLS (e.g. sslmode=disable) or redirecting connections. This is a classic connection-string injection pattern.

### [medium] Process spawning

Finding ID: `NPS-421844485C0B`

File: `main.go:175`

preRun() uses exec.LookPath and later boilingcore registers the driver binary path; the driver is executed as an external process. While expected for this tool, the driver name/path is derived from user input and may be manipulated (e.g. path traversal via os.PathSeparator check) to execute an arbitrary binary.

### [medium] Environment variable harvesting

Finding ID: `NPS-304124D6AC14`

File: `main.go:220`

allKeys() iterates over os.Environ() and collects all environment variables matching a prefix derived from user-supplied driver name, which could inadvertently capture sensitive environment variables (e.g. API keys, credentials) if they share the prefix. This data is then placed into DriverConfig and potentially passed to the driver binary.

### [low] Potential information disclosure via error handling

Finding ID: `NPS-DB2AB2829C69`

File: `drivers/binary_driver.go:75`

Error messages include the executable path and may leak details about the environment or configuration. While not directly malicious, verbose error messages could aid attackers in reconnaissance.

### [low] Untrusted input handling / missing bounds check

Finding ID: `NPS-7006B259C9E6`

File: `drivers/driver_main.go:11`

os.Args[1] is accessed directly without verifying len(os.Args) > 1, which would cause a panic if the binary is invoked with no arguments. More importantly, the 'method' value is used to select driver behavior; if the driver implementation is supplied by a third party and the dispatcher is generic, unexpected methods are silently ignored (output remains nil), which could mask errors.

### [low] Potential information disclosure via verbose error output

Finding ID: `NPS-C5CC27A04F91`

File: `drivers/driver_main.go:24`

When JSON parsing fails, the error handler prints the entire raw input buffer (b) to stderr. If the config contains secrets (tokens, credentials, environment-specific values), they could be leaked into logs or CI output. This is a minor concern for a driver helper but worth noting.

### [low] init() function registration

Finding ID: `NPS-0E8499644FCA`

File: `drivers/mocks/mock.go:8`

The init() function registers a mock driver with the sqlboiler driver registry. This is a standard Go pattern for plugin registration in test/mock packages and does not perform any suspicious activity such as network access, file system manipulation, or code execution.

### [low] Panic recovery using unsafe type assertion

Finding ID: `NPS-64A5A0FE2DA8`

File: `drivers/sqlboiler-psql/driver/psql.go:79`

The deferred recover in Assemble does `err = r.(error)`, which will itself panic if the recovered value is not an error (e.g. a string panic). This is not directly malicious, but it can crash the generator in unexpected ways and is a robustness concern rather than a security exploit.

### [low] Weak default TLS policy

Finding ID: `NPS-3068265D1F0E`

File: `drivers/sqlboiler-psql/driver/psql.go:90`

The default sslmode is set to 'require' which encrypts traffic but does not verify the server certificate (no hostname/cert verification). An attacker in a MITM position could impersonate the database server. Prefer 'verify-full' or 'verify-ca' for stronger guarantees.

### [low] Unbounded stderr output of database-derived identifiers

Finding ID: `NPS-8FA2EBAE46F8`

File: `drivers/sqlboiler-psql/driver/psql.go:538`

In TranslateColumnType, `fmt.Fprintf(os.Stderr, "warning: incompatible data type detected: %s\n", c.UDTName)` writes a database-controlled UDT name to stderr. While not a direct code execution vector, writing unsanitized database metadata to a terminal could enable terminal escape sequence injection if output is later reviewed in a vulnerable terminal. Typically low impact.

### [low] File system manipulation

Finding ID: `NPS-5DAE8646DE92`

File: `main.go:118`

The --wipe flag causes deletion of the output folder (rm -rf) before generation. If the output path is misconfigured or influenced by environment/config, it could delete unintended directories.

### [low] Dynamic code execution via templates

Finding ID: `NPS-91AE7DF9739D`

File: `main.go:150`

TemplateDirs and Replacements flags allow specifying external template directories and replacement files, which are processed at generation time. Malicious templates could execute arbitrary code within the generation context, though this is an intended feature.

### [low] Input validation using regex

Finding ID: `NPS-FEC5C111309D`

File: `queries/query_builders.go`

Uses rgxIdentifier and rgxInClause to validate and quote identifiers, reducing SQL injection risk.

### [low] SQL string concatenation

Finding ID: `NPS-3B6830BCB3F1`

File: `queries/query_builders.go`

Multiple places build SQL via string concatenation and fmt.Fprintf; however, identifiers are quoted and values use placeholders, mitigating injection.

### [low] Panic on invalid SQL structure

Finding ID: `NPS-71934E381295`

File: `queries/query_builders.go`

Calls panic in convertInQuestionMarks, convertQuestionMarks, whereClause, and buildSelectQuery (unsupported join kind). This is a reliability concern, not a security vulnerability.

## Files reviewed

- `drivers/binary_driver.go` (medium): The code spawns external binaries based on unvalidated input from driver configuration, which could lead to arbitrary command execution if the driver name is attacker-controlled; this is a medium-severity concern in a trusted driver context but warrants attention.
- `drivers/driver_main.go` (medium): The file is a generic CLI dispatcher for driver plugins; it contains no exfiltration, credential harvesting, code execution, or network activity, but does leak raw stdin on JSON parse errors and lacks argument validation.
- `drivers/sqlboiler-psql/driver/psql.go` (medium): No malicious code found; the driver is a legitimate sqlboiler PostgreSQL generator, but it builds connection strings via unsanitized string interpolation and defaults to a non-verifying SSL mode, which are minor security hygiene concerns rather than signs of malicious intent.
- `main.go` (medium): The code is a legitimate CLI tool but contains patterns that could be abused if inputs are malicious, including environment variable collection, external binary execution, template-based code generation, and destructive file operations.
- `boil/columns.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/db.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/global.go` (safe): No malicious patterns detected
- `boil/hooks.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/aliases.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/boilingcore.go` (safe): No malicious patterns detected; the code is a legitimate SQLBoiler code generation library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `boilingcore/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/output.go` (safe): No malicious patterns detected; the code is a legitimate Go code generator that writes template output to files under a configured output folder.
- `boilingcore/templates.go` (safe): No malicious patterns detected in the provided Go source code.
- `boilingcore/text_helpers.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/column.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/config.go` (safe): No malicious patterns detected; the code is a straightforward configuration utility with type assertions and no network, filesystem, or process manipulation.
- `drivers/interface.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/keys.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/mocks/mock.go` (safe): The code is a benign mock database driver implementation with no malicious patterns detected.
- `drivers/registration.go` (safe): No malicious patterns detected
- `drivers/relationships.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-mssql/driver/bindata.go` (safe): No malicious patterns detected; this is standard go-bindata generated code for embedding template files.
- `drivers/sqlboiler-mssql/driver/mssql.go` (safe): No malicious patterns detected: the code is a legitimate MSSQL driver for SQLBoiler with standard database operations and no exfiltration, credential harvesting, obfuscation, or backdoors.
- `drivers/sqlboiler-mssql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-mysql/driver/bindata.go` (safe): No malicious patterns detected; this is a standard go-bindata generated file embedding template data, with no network calls, exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious install/import-time behavior.
- `drivers/sqlboiler-mysql/driver/mysql.go` (safe): This is a legitimate MySQL driver implementation for sqlboiler that performs standard database introspection queries with no malicious patterns detected.
- `drivers/sqlboiler-mysql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-psql/driver/bindata.go` (safe): This is a standard go-bindata generated file that embeds gzipped template assets for the sqlboiler-psql driver, with no malicious patterns detected.
- `drivers/sqlboiler-psql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `importers/imports.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/eager_load.go` (safe): No malicious patterns detected
- `queries/helpers.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/qm/query_mods.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/qmhelper/qmhelper.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/query.go` (safe): No malicious patterns detected in this SQL query builder code; it contains no exfiltration, credential harvesting, obfuscation, process spawning, or network activity.
- `queries/query_builders.go` (safe): No malicious patterns such as exfiltration, credential harvesting, obfuscation, code execution, or network activity were found; the code is a legitimate SQL query builder with standard input validation.
- `queries/reflect.go` (safe): No malicious patterns detected
- `randomize/random.go` (safe): No malicious patterns detected; the code is a legitimate random data generation library for database testing.
- `randomize/randomize.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/buf_pool.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/inflect.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/sets.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/strmangle.go` (safe): No malicious patterns detected in this string manipulation utility package.
- `types/array.go` (safe): No malicious patterns detected; the code is a standard PostgreSQL array type implementation with no network, filesystem, process, or obfuscation concerns.
- `types/byte.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/decimal.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/hstore.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/json.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/box.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/circle.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/general.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/line.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/lseg.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullBox.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullCircle.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullLine.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullLseg.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPath.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPoint.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPolygon.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/path.go` (safe): No malicious patterns detected
- `types/pgeo/point.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/polygon.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
