# github.com/urfave/cli/v2@v2.27.7 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:13.000Z
- Files reviewed: 47
- Findings: 5 medium, 10 low severity findings
- Report: https://security.togoder.click/go/github.com/urfave/cli/v2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/urfave/cli/v2@v2.27.7 on Oct 5, 2026. An AI review of 47 source files produced 5 medium, 10 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unrestricted Remote File Loading

Finding ID: `NPS-C543482372DC`

File: `altsrc/yaml_file_loader.go:63`

loadDataFrom supports fetching configuration over http/https via http.Get when the provided path is a URL with a host. This allows loading YAML configuration from arbitrary remote endpoints, which can be a vector for remote code/config injection or SSRF in some contexts. Additionally, the HTTP response body is read without checking res.StatusCode or limiting size, so a large or error response could cause unexpected behavior or resource exhaustion.

### [medium] Network Request with External Input

Finding ID: `NPS-0CF3B4260AA0`

File: `altsrc/yaml_file_loader.go:63`

filePath is passed directly to http.Get after being parsed by url.Parse. If filePath is attacker-influenced (e.g., via a CLI flag), this enables SSRF or downloading attacker-controlled YAML that then gets unmarshaled and may influence application behavior.

### [medium] Command execution

Finding ID: `NPS-DDC0C6813C5B`

File: `internal/build/build.go:155`

The build script extensively uses os/exec to run external commands such as git, go, bash, goimports, yq, pip, mkdocs, gfmrun, and diff. While this is expected for a build script similar to a Makefile, it creates a large attack surface if any arguments are influenced by untrusted input.

### [medium] Network download and execution

Finding ID: `NPS-0DF37EE06C2F`

File: `internal/build/build.go:459`

EnsureGfmrunActionFunc downloads a binary from GitHub releases over HTTP(S) and writes it to a local .local/bin directory with executable permissions, then later executes it. If the remote URL or release artifacts were compromised, this could lead to arbitrary code execution. The download uses http.DefaultClient without certificate pinning or hash verification.

### [medium] Credential handling

Finding ID: `NPS-BEA9DA124850`

File: `internal/build/build.go:520`

SetMkdocsRemoteActionFunc reads a GitHub token from an environment variable or CLI flag and embeds it directly into a git remote URL (https://x-access-token:TOKEN@github.com/...). This can expose the token in process listings, shell history, and git configuration.

### [low] File system path manipulation

Finding ID: `NPS-DFC152F59072`

File: `altsrc/flag.go:260`

The PathFlag ApplyInputSourceValue method uses filepath.Abs and filepath.Join to resolve relative paths based on the input source location. This is expected behavior for resolving config file paths, but could potentially lead to path traversal if the input source paths are attacker-controlled. No direct write or read operations are performed outside expected scope.

### [low] Environment variable access

Finding ID: `NPS-8B0AE7746FF0`

File: `altsrc/flag.go:356`

The code reads environment variables via syscall.Getenv to check if flags are already set from environment sources. This is a legitimate feature for the altsrc package (used to load flag values from alternative input sources like config files), but environment variable access can be abused if the package is malicious. In this case, it appears benign.

### [low] Unsafe type assertions

Finding ID: `NPS-5F1F07D5E886`

File: `altsrc/toml_file_loader.go:16`

The unmarshalMap function uses unchecked type assertions (v.Interface().(map[string]interface{}), val.(bool), etc.) without validating the underlying type. A malformed TOML file could cause a panic, leading to a denial of service. The function first asserts i to map[string]interface{} without a check, and subsequent assertions assume the switch case guarantees the type, which is true for the value but not for the initial interface assertion.

### [low] Potential panic via nil map access

Finding ID: `NPS-22FE27510624`

File: `altsrc/toml_file_loader.go:16`

If the TOML input contains a map with non-string keys, the type assertion m := i.(map[string]interface{}) will panic. The TOML parser typically produces map[string]interface{}, but malformed or crafted input could result in a different type, causing a panic. This is a robustness issue rather than a security vulnerability, but it could be exploited for denial of service.

### [low] Process termination via os.Exit

Finding ID: `NPS-1FAB8DF3B250`

File: `errors.go:10`

The code exposes OsExiter = os.Exit and calls it in HandleExitCoder, which terminates the process. This is intended behavior for a CLI library (urfave/cli) to propagate exit codes, not a malicious backdoor.

### [low] Global writer override

Finding ID: `NPS-70305821B12D`

File: `errors.go:14`

ErrWriter is a package-level io.Writer defaulting to os.Stderr; it can be reassigned by importers to redirect error output, which is a benign extension point for CLI libraries.

### [low] Potential command injection via generated shell completion

Finding ID: `NPS-1A30E5034B93`

File: `fish.go`

The code generates fish shell completion scripts using flag names, command names, and usage strings without full shell escaping. The only escaping performed is for single quotes (escapeSingleQuotes). If an application developer passes attacker-controlled data (e.g. a command usage string containing newlines and shell metacharacters such as a double quote, backtick, or $()) into the App/Command/Flag definitions, the generated completion script could contain injected shell commands that execute when the user sources the completion output. This is a latent injection sink, though it requires the caller to control the inputs and is not a self-executing malicious payload. It is a common pattern in libraries like urfave/cli.

### [low] json-deserialization

Finding ID: `NPS-482B90D06EE2`

File: `flag_int64_slice.go:37`

The Set method uses json.Unmarshal on user-supplied string content when it begins with a special prefix (slPfx). The unmarshal target is a typed []int64 slice via a pointer to i.slice, so it cannot be used for arbitrary type confusion, code execution, or object injection. Error is ignored but the slice type constrains the parsed data to integers.

### [low] File system manipulation

Finding ID: `NPS-58D7109BD29F`

File: `internal/build/build.go:239`

The script creates temporary directories, changes working directories, writes coverage and documentation files, and removes files (e.g., os.RemoveAll(tmpDir), os.Remove for coverprofiles, git remote remove). These operations are within the project scope but could be abused if paths are manipulated.

### [low] Process execution with external binaries

Finding ID: `NPS-5BA87EA904E8`

File: `internal/build/build.go:444`

Several actions install or invoke third-party tools (goimports, gfmrun, pip packages) from remote sources at build time. Installing 'latest' versions of tools without version pinning can introduce supply-chain risk.

## Files reviewed

- `altsrc/flag.go` (medium): The code is part of the legitimate urfave/cli altsrc package and contains no malicious patterns; only benign environment variable access and path manipulation for configuration loading.
- `altsrc/toml_file_loader.go` (medium): The code appears to be a legitimate TOML configuration loader for urfave/cli with only minor robustness concerns related to unchecked type assertions that could cause panics on malformed input; no malicious patterns were detected.
- `altsrc/yaml_file_loader.go` (medium): The file loader supports remote http/https fetching of YAML configuration without response validation or size limits, presenting SSRF and remote config injection risks, but no clear malicious exfiltration, credential harvesting, or code execution patterns were found.
- `internal/build/build.go` (medium): This is a legitimate build script for the urfave/cli project that uses expected build tooling, but it contains command execution, unverified binary downloads, and credential embedding that warrant caution.
- `altsrc/default_input_source.go` (safe): Cleared by Jev triage; no further analysis needed
- `altsrc/flag_generated.go` (safe): Cleared by Jev triage; no further analysis needed
- `altsrc/input_source_context.go` (safe): Cleared by Jev triage; no further analysis needed
- `altsrc/json_source_context.go` (safe): No malicious patterns detected
- `altsrc/map_input_source.go` (safe): Cleared by Jev triage; no further analysis needed
- `app.go` (safe): Cleared by Jev triage; no further analysis needed
- `args.go` (safe): Cleared by Jev triage; no further analysis needed
- `category.go` (safe): Cleared by Jev triage; no further analysis needed
- `cli.go` (safe): No malicious patterns detected; the file contains only package documentation and a code generation directive.
- `command.go` (safe): Cleared by Jev triage; no further analysis needed
- `context.go` (safe): Cleared by Jev triage; no further analysis needed
- `docs.go` (safe): No malicious patterns detected; the code is a legitimate documentation generator for the urfave/cli library that only performs local template rendering and markdown/man page conversion without network, filesystem, or process side effects.
- `errors.go` (safe): This is the standard errors.go from the urfave/cli Go library; it contains no exfiltration, credential harvesting, obfuscation, network activity, or other malicious patterns.
- `fish.go` (safe): No malicious patterns detected; the file only builds a fish shell completion template from application-provided names, usages, and flags, with no network, filesystem, process execution, or credential access.
- `flag.go` (safe): No malicious patterns detected; this is standard CLI flag handling code from the urfave/cli library with no exfiltration, credential harvesting, or suspicious execution behavior.
- `flag_bool.go` (safe): No malicious patterns detected
- `flag_duration.go` (safe): No malicious patterns detected; the code is a standard CLI duration flag implementation with no data exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity.
- `flag_ext.go` (safe): Cleared by Jev triage; no further analysis needed
- `flag_float64.go` (safe): No malicious patterns detected; the file contains standard CLI flag handling for a float64 flag with environment/file input parsing.
- `flag_float64_slice.go` (safe): No malicious patterns detected; the code is a standard CLI flag implementation for float64 slices with JSON serialization and no network, filesystem, process, or credential access.
- `flag_generic.go` (safe): No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, harvesting, obfuscation, or process execution.
- `flag_int.go` (safe): No malicious patterns detected in the Go flag implementation; the code performs standard CLI flag parsing and environment/file variable resolution without exfiltration, obfuscation, or suspicious system interaction.
- `flag_int64.go` (safe): No malicious patterns detected
- `flag_int64_slice.go` (safe): No malicious patterns detected; the code is a standard CLI flag value type handling int64 slices with no network, process, file, environment, or dynamic execution risks.
- `flag_int_slice.go` (safe): No malicious patterns detected
- `flag_path.go` (safe): No malicious patterns detected
- `flag_string.go` (safe): No malicious patterns detected; the code is standard Go CLI flag handling with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `flag_string_slice.go` (safe): No malicious patterns detected; the code is a standard CLI flag implementation for handling string slices.
- `flag_timestamp.go` (safe): No malicious patterns detected; this is a standard CLI timestamp flag implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `flag_uint.go` (safe): No malicious patterns detected; the code is a standard CLI flag implementation for parsing unsigned integers from flags and environment variables without any exfiltration, code execution, or other suspicious behavior.
- `flag_uint64.go` (safe): No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, obfuscation, or suspicious behavior.
- `flag_uint64_slice.go` (safe): No malicious patterns detected
- `flag_uint_slice.go` (safe): No malicious patterns detected; the code implements a standard CLI flag type for uint slices with parsing, serialization, and environment variable support, with no exfiltration, credential harvesting, obfuscation, or other red flags.
- `funcs.go` (safe): Cleared by Jev triage; no further analysis needed
- `help.go` (safe): No malicious patterns detected; this is standard Go CLI help rendering code.
- `internal/example-cli/example-cli.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/example-hello-world/example-hello-world.go` (safe): Cleared by Jev triage; no further analysis needed
- `parse.go` (safe): Cleared by Jev triage; no further analysis needed
- `sliceflag.go` (safe): Cleared by Jev triage; no further analysis needed
- `sort.go` (safe): Cleared by Jev triage; no further analysis needed
- `suggestions.go` (safe): The code is a legitimate CLI suggestion utility using the smetrics library for string similarity; no malicious patterns, network calls, credential theft, or dynamic execution were found.
- `template.go` (safe): No malicious patterns detected; the file contains Go text/template definitions for CLI help output with no execution, network, or filesystem activity.
- `zz_generated.flags.go` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
