Summary
Togoder Security scanned the Go package github.com/urfave/cli/v2@v2.27.7 on Oct 5, 2026. An AI review of 47 source files produced 5 medium, 10 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 15
Unrestricted Remote File Loading
NPS-C543482372DC
loadDataFrom supports fetching configuration over http/https via http.Get when the provided path is a URL with a host. This allows loading YAML configuration from arbitrary remote endpoints, which can be a vector for remote code/config injection or SSRF in some contexts. Additionally, the HTTP response body is read without checking res.StatusCode or limiting size, so a large or error response could cause unexpected behavior or resource exhaustion.
Network Request with External Input
NPS-0CF3B4260AA0
filePath is passed directly to http.Get after being parsed by url.Parse. If filePath is attacker-influenced (e.g., via a CLI flag), this enables SSRF or downloading attacker-controlled YAML that then gets unmarshaled and may influence application behavior.
Command execution
NPS-DDC0C6813C5B
The build script extensively uses os/exec to run external commands such as git, go, bash, goimports, yq, pip, mkdocs, gfmrun, and diff. While this is expected for a build script similar to a Makefile, it creates a large attack surface if any arguments are influenced by untrusted input.
Network download and execution
NPS-0DF37EE06C2F
EnsureGfmrunActionFunc downloads a binary from GitHub releases over HTTP(S) and writes it to a local .local/bin directory with executable permissions, then later executes it. If the remote URL or release artifacts were compromised, this could lead to arbitrary code execution. The download uses http.DefaultClient without certificate pinning or hash verification.
Credential handling
NPS-BEA9DA124850
SetMkdocsRemoteActionFunc reads a GitHub token from an environment variable or CLI flag and embeds it directly into a git remote URL (https://x-access-token:TOKEN@github.com/...). This can expose the token in process listings, shell history, and git configuration.
File system path manipulation
NPS-DFC152F59072
The PathFlag ApplyInputSourceValue method uses filepath.Abs and filepath.Join to resolve relative paths based on the input source location. This is expected behavior for resolving config file paths, but could potentially lead to path traversal if the input source paths are attacker-controlled. No direct write or read operations are performed outside expected scope.
Environment variable access
NPS-8B0AE7746FF0
The code reads environment variables via syscall.Getenv to check if flags are already set from environment sources. This is a legitimate feature for the altsrc package (used to load flag values from alternative input sources like config files), but environment variable access can be abused if the package is malicious. In this case, it appears benign.
Unsafe type assertions
NPS-5F1F07D5E886
The unmarshalMap function uses unchecked type assertions (v.Interface().(map[string]interface{}), val.(bool), etc.) without validating the underlying type. A malformed TOML file could cause a panic, leading to a denial of service. The function first asserts i to map[string]interface{} without a check, and subsequent assertions assume the switch case guarantees the type, which is true for the value but not for the initial interface assertion.
Potential panic via nil map access
NPS-22FE27510624
If the TOML input contains a map with non-string keys, the type assertion m := i.(map[string]interface{}) will panic. The TOML parser typically produces map[string]interface{}, but malformed or crafted input could result in a different type, causing a panic. This is a robustness issue rather than a security vulnerability, but it could be exploited for denial of service.
Process termination via os.Exit
NPS-1FAB8DF3B250
The code exposes OsExiter = os.Exit and calls it in HandleExitCoder, which terminates the process. This is intended behavior for a CLI library (urfave/cli) to propagate exit codes, not a malicious backdoor.
Global writer override
NPS-70305821B12D
ErrWriter is a package-level io.Writer defaulting to os.Stderr; it can be reassigned by importers to redirect error output, which is a benign extension point for CLI libraries.
Potential command injection via generated shell completion
NPS-1A30E5034B93
The code generates fish shell completion scripts using flag names, command names, and usage strings without full shell escaping. The only escaping performed is for single quotes (escapeSingleQuotes). If an application developer passes attacker-controlled data (e.g. a command usage string containing newlines and shell metacharacters such as a double quote, backtick, or $()) into the App/Command/Flag definitions, the generated completion script could contain injected shell commands that execute when the user sources the completion output. This is a latent injection sink, though it requires the caller to control the inputs and is not a self-executing malicious payload. It is a common pattern in libraries like urfave/cli.
json-deserialization
NPS-482B90D06EE2
The Set method uses json.Unmarshal on user-supplied string content when it begins with a special prefix (slPfx). The unmarshal target is a typed []int64 slice via a pointer to i.slice, so it cannot be used for arbitrary type confusion, code execution, or object injection. Error is ignored but the slice type constrains the parsed data to integers.
File system manipulation
NPS-58D7109BD29F
The script creates temporary directories, changes working directories, writes coverage and documentation files, and removes files (e.g., os.RemoveAll(tmpDir), os.Remove for coverprofiles, git remote remove). These operations are within the project scope but could be abused if paths are manipulated.
Process execution with external binaries
NPS-5BA87EA904E8
Several actions install or invoke third-party tools (goimports, gfmrun, pip packages) from remote sources at build time. Installing 'latest' versions of tools without version pinning can introduce supply-chain risk.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| altsrc/flag.go | medium | The code is part of the legitimate urfave/cli altsrc package and contains no malicious patterns; only benign environment variable access and path manipulation for configuration loading. |
| altsrc/toml_file_loader.go | medium | The code appears to be a legitimate TOML configuration loader for urfave/cli with only minor robustness concerns related to unchecked type assertions that could cause panics on malformed input; no malicious patterns were detected. |
| altsrc/yaml_file_loader.go | medium | The file loader supports remote http/https fetching of YAML configuration without response validation or size limits, presenting SSRF and remote config injection risks, but no clear malicious exfiltration, credential harvesting, or code execution patterns were found. |
| internal/build/build.go | medium | This is a legitimate build script for the urfave/cli project that uses expected build tooling, but it contains command execution, unverified binary downloads, and credential embedding that warrant caution. |
| altsrc/default_input_source.go | safe | Cleared by Jev triage; no further analysis needed |
| altsrc/flag_generated.go | safe | Cleared by Jev triage; no further analysis needed |
| altsrc/input_source_context.go | safe | Cleared by Jev triage; no further analysis needed |
| altsrc/json_source_context.go | safe | No malicious patterns detected |
| altsrc/map_input_source.go | safe | Cleared by Jev triage; no further analysis needed |
| app.go | safe | Cleared by Jev triage; no further analysis needed |
| args.go | safe | Cleared by Jev triage; no further analysis needed |
| category.go | safe | Cleared by Jev triage; no further analysis needed |
| cli.go | safe | No malicious patterns detected; the file contains only package documentation and a code generation directive. |
| command.go | safe | Cleared by Jev triage; no further analysis needed |
| context.go | safe | Cleared by Jev triage; no further analysis needed |
| docs.go | safe | No malicious patterns detected; the code is a legitimate documentation generator for the urfave/cli library that only performs local template rendering and markdown/man page conversion without network, filesystem, or process side effects. |
| errors.go | safe | This is the standard errors.go from the urfave/cli Go library; it contains no exfiltration, credential harvesting, obfuscation, network activity, or other malicious patterns. |
| fish.go | safe | No malicious patterns detected; the file only builds a fish shell completion template from application-provided names, usages, and flags, with no network, filesystem, process execution, or credential access. |
| flag.go | safe | No malicious patterns detected; this is standard CLI flag handling code from the urfave/cli library with no exfiltration, credential harvesting, or suspicious execution behavior. |
| flag_bool.go | safe | No malicious patterns detected |
| flag_duration.go | safe | No malicious patterns detected; the code is a standard CLI duration flag implementation with no data exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity. |
| flag_ext.go | safe | Cleared by Jev triage; no further analysis needed |
| flag_float64.go | safe | No malicious patterns detected; the file contains standard CLI flag handling for a float64 flag with environment/file input parsing. |
| flag_float64_slice.go | safe | No malicious patterns detected; the code is a standard CLI flag implementation for float64 slices with JSON serialization and no network, filesystem, process, or credential access. |
| flag_generic.go | safe | No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, harvesting, obfuscation, or process execution. |
Show 22 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| flag_int.go | safe | No malicious patterns detected in the Go flag implementation; the code performs standard CLI flag parsing and environment/file variable resolution without exfiltration, obfuscation, or suspicious system interaction. |
| flag_int64.go | safe | No malicious patterns detected |
| flag_int64_slice.go | safe | No malicious patterns detected; the code is a standard CLI flag value type handling int64 slices with no network, process, file, environment, or dynamic execution risks. |
| flag_int_slice.go | safe | No malicious patterns detected |
| flag_path.go | safe | No malicious patterns detected |
| flag_string.go | safe | No malicious patterns detected; the code is standard Go CLI flag handling with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| flag_string_slice.go | safe | No malicious patterns detected; the code is a standard CLI flag implementation for handling string slices. |
| flag_timestamp.go | safe | No malicious patterns detected; this is a standard CLI timestamp flag implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| flag_uint.go | safe | No malicious patterns detected; the code is a standard CLI flag implementation for parsing unsigned integers from flags and environment variables without any exfiltration, code execution, or other suspicious behavior. |
| flag_uint64.go | safe | No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, obfuscation, or suspicious behavior. |
| flag_uint64_slice.go | safe | No malicious patterns detected |
| flag_uint_slice.go | safe | No malicious patterns detected; the code implements a standard CLI flag type for uint slices with parsing, serialization, and environment variable support, with no exfiltration, credential harvesting, obfuscation, or other red flags. |
| funcs.go | safe | Cleared by Jev triage; no further analysis needed |
| help.go | safe | No malicious patterns detected; this is standard Go CLI help rendering code. |
| internal/example-cli/example-cli.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/example-hello-world/example-hello-world.go | safe | Cleared by Jev triage; no further analysis needed |
| parse.go | safe | Cleared by Jev triage; no further analysis needed |
| sliceflag.go | safe | Cleared by Jev triage; no further analysis needed |
| sort.go | safe | Cleared by Jev triage; no further analysis needed |
| suggestions.go | safe | The code is a legitimate CLI suggestion utility using the smetrics library for string similarity; no malicious patterns, network calls, credential theft, or dynamic execution were found. |
| template.go | safe | No malicious patterns detected; the file contains Go text/template definitions for CLI help output with no execution, network, or filesystem activity. |
| zz_generated.flags.go | safe | No malicious patterns detected |
Scanned versions of github.com/urfave/cli/v2
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v2.27.7 | Needs review | 47 | Oct 5, 2026 |
Frequently asked questions
Is github.com/urfave/cli/v2 safe to use?
No confirmed malware was found in github.com/urfave/cli/v2@v2.27.7, but the review flagged 5 medium, 10 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/urfave/cli/v2 contain malware?
No malware was identified in github.com/urfave/cli/v2@v2.27.7 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/urfave/cli/v2 checked?
Togoder Security downloaded the published Go package and had an AI model read its 47 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/urfave/cli/v2 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/urfave/cli/v2@v2.27.7, cost nothing.