Togoder security

Go package security report

github.com/urfave/cli/v2@v2.27.7 security report

Risky patterns found that deserve a look.

Needs review Version v2.27.7 Files reviewed 47 Size 234.3 KB Scanned

Summary

Togoder Security scanned the Go package github.com/urfave/cli/v2@v2.27.7 on Oct 5, 2026. An AI review of 47 source files produced 5 medium, 10 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
10
low

Findings 15

medium

Unrestricted Remote File Loading

NPS-C543482372DC

loadDataFrom supports fetching configuration over http/https via http.Get when the provided path is a URL with a host. This allows loading YAML configuration from arbitrary remote endpoints, which can be a vector for remote code/config injection or SSRF in some contexts. Additionally, the HTTP response body is read without checking res.StatusCode or limiting size, so a large or error response could cause unexpected behavior or resource exhaustion.

altsrc/yaml_file_loader.go:63
medium

Network Request with External Input

NPS-0CF3B4260AA0

filePath is passed directly to http.Get after being parsed by url.Parse. If filePath is attacker-influenced (e.g., via a CLI flag), this enables SSRF or downloading attacker-controlled YAML that then gets unmarshaled and may influence application behavior.

altsrc/yaml_file_loader.go:63
medium

Command execution

NPS-DDC0C6813C5B

The build script extensively uses os/exec to run external commands such as git, go, bash, goimports, yq, pip, mkdocs, gfmrun, and diff. While this is expected for a build script similar to a Makefile, it creates a large attack surface if any arguments are influenced by untrusted input.

internal/build/build.go:155
medium

Network download and execution

NPS-0DF37EE06C2F

EnsureGfmrunActionFunc downloads a binary from GitHub releases over HTTP(S) and writes it to a local .local/bin directory with executable permissions, then later executes it. If the remote URL or release artifacts were compromised, this could lead to arbitrary code execution. The download uses http.DefaultClient without certificate pinning or hash verification.

internal/build/build.go:459
medium

Credential handling

NPS-BEA9DA124850

SetMkdocsRemoteActionFunc reads a GitHub token from an environment variable or CLI flag and embeds it directly into a git remote URL (https://x-access-token:TOKEN@github.com/...). This can expose the token in process listings, shell history, and git configuration.

internal/build/build.go:520
low

File system path manipulation

NPS-DFC152F59072

The PathFlag ApplyInputSourceValue method uses filepath.Abs and filepath.Join to resolve relative paths based on the input source location. This is expected behavior for resolving config file paths, but could potentially lead to path traversal if the input source paths are attacker-controlled. No direct write or read operations are performed outside expected scope.

altsrc/flag.go:260
low

Environment variable access

NPS-8B0AE7746FF0

The code reads environment variables via syscall.Getenv to check if flags are already set from environment sources. This is a legitimate feature for the altsrc package (used to load flag values from alternative input sources like config files), but environment variable access can be abused if the package is malicious. In this case, it appears benign.

altsrc/flag.go:356
low

Unsafe type assertions

NPS-5F1F07D5E886

The unmarshalMap function uses unchecked type assertions (v.Interface().(map[string]interface{}), val.(bool), etc.) without validating the underlying type. A malformed TOML file could cause a panic, leading to a denial of service. The function first asserts i to map[string]interface{} without a check, and subsequent assertions assume the switch case guarantees the type, which is true for the value but not for the initial interface assertion.

altsrc/toml_file_loader.go:16
low

Potential panic via nil map access

NPS-22FE27510624

If the TOML input contains a map with non-string keys, the type assertion m := i.(map[string]interface{}) will panic. The TOML parser typically produces map[string]interface{}, but malformed or crafted input could result in a different type, causing a panic. This is a robustness issue rather than a security vulnerability, but it could be exploited for denial of service.

altsrc/toml_file_loader.go:16
low

Process termination via os.Exit

NPS-1FAB8DF3B250

The code exposes OsExiter = os.Exit and calls it in HandleExitCoder, which terminates the process. This is intended behavior for a CLI library (urfave/cli) to propagate exit codes, not a malicious backdoor.

errors.go:10
low

Global writer override

NPS-70305821B12D

ErrWriter is a package-level io.Writer defaulting to os.Stderr; it can be reassigned by importers to redirect error output, which is a benign extension point for CLI libraries.

errors.go:14
low

Potential command injection via generated shell completion

NPS-1A30E5034B93

The code generates fish shell completion scripts using flag names, command names, and usage strings without full shell escaping. The only escaping performed is for single quotes (escapeSingleQuotes). If an application developer passes attacker-controlled data (e.g. a command usage string containing newlines and shell metacharacters such as a double quote, backtick, or $()) into the App/Command/Flag definitions, the generated completion script could contain injected shell commands that execute when the user sources the completion output. This is a latent injection sink, though it requires the caller to control the inputs and is not a self-executing malicious payload. It is a common pattern in libraries like urfave/cli.

fish.go
low

json-deserialization

NPS-482B90D06EE2

The Set method uses json.Unmarshal on user-supplied string content when it begins with a special prefix (slPfx). The unmarshal target is a typed []int64 slice via a pointer to i.slice, so it cannot be used for arbitrary type confusion, code execution, or object injection. Error is ignored but the slice type constrains the parsed data to integers.

flag_int64_slice.go:37
low

File system manipulation

NPS-58D7109BD29F

The script creates temporary directories, changes working directories, writes coverage and documentation files, and removes files (e.g., os.RemoveAll(tmpDir), os.Remove for coverprofiles, git remote remove). These operations are within the project scope but could be abused if paths are manipulated.

internal/build/build.go:239
low

Process execution with external binaries

NPS-5BA87EA904E8

Several actions install or invoke third-party tools (goimports, gfmrun, pip packages) from remote sources at build time. Installing 'latest' versions of tools without version pinning can introduce supply-chain risk.

internal/build/build.go:444

Files reviewed

FileVerdictWhat the reviewer saw
altsrc/flag.go medium The code is part of the legitimate urfave/cli altsrc package and contains no malicious patterns; only benign environment variable access and path manipulation for configuration loading.
altsrc/toml_file_loader.go medium The code appears to be a legitimate TOML configuration loader for urfave/cli with only minor robustness concerns related to unchecked type assertions that could cause panics on malformed input; no malicious patterns were detected.
altsrc/yaml_file_loader.go medium The file loader supports remote http/https fetching of YAML configuration without response validation or size limits, presenting SSRF and remote config injection risks, but no clear malicious exfiltration, credential harvesting, or code execution patterns were found.
internal/build/build.go medium This is a legitimate build script for the urfave/cli project that uses expected build tooling, but it contains command execution, unverified binary downloads, and credential embedding that warrant caution.
altsrc/default_input_source.go safe Cleared by Jev triage; no further analysis needed
altsrc/flag_generated.go safe Cleared by Jev triage; no further analysis needed
altsrc/input_source_context.go safe Cleared by Jev triage; no further analysis needed
altsrc/json_source_context.go safe No malicious patterns detected
altsrc/map_input_source.go safe Cleared by Jev triage; no further analysis needed
app.go safe Cleared by Jev triage; no further analysis needed
args.go safe Cleared by Jev triage; no further analysis needed
category.go safe Cleared by Jev triage; no further analysis needed
cli.go safe No malicious patterns detected; the file contains only package documentation and a code generation directive.
command.go safe Cleared by Jev triage; no further analysis needed
context.go safe Cleared by Jev triage; no further analysis needed
docs.go safe No malicious patterns detected; the code is a legitimate documentation generator for the urfave/cli library that only performs local template rendering and markdown/man page conversion without network, filesystem, or process side effects.
errors.go safe This is the standard errors.go from the urfave/cli Go library; it contains no exfiltration, credential harvesting, obfuscation, network activity, or other malicious patterns.
fish.go safe No malicious patterns detected; the file only builds a fish shell completion template from application-provided names, usages, and flags, with no network, filesystem, process execution, or credential access.
flag.go safe No malicious patterns detected; this is standard CLI flag handling code from the urfave/cli library with no exfiltration, credential harvesting, or suspicious execution behavior.
flag_bool.go safe No malicious patterns detected
flag_duration.go safe No malicious patterns detected; the code is a standard CLI duration flag implementation with no data exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity.
flag_ext.go safe Cleared by Jev triage; no further analysis needed
flag_float64.go safe No malicious patterns detected; the file contains standard CLI flag handling for a float64 flag with environment/file input parsing.
flag_float64_slice.go safe No malicious patterns detected; the code is a standard CLI flag implementation for float64 slices with JSON serialization and no network, filesystem, process, or credential access.
flag_generic.go safe No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, harvesting, obfuscation, or process execution.
Show 22 more files
FileVerdictWhat the reviewer saw
flag_int.go safe No malicious patterns detected in the Go flag implementation; the code performs standard CLI flag parsing and environment/file variable resolution without exfiltration, obfuscation, or suspicious system interaction.
flag_int64.go safe No malicious patterns detected
flag_int64_slice.go safe No malicious patterns detected; the code is a standard CLI flag value type handling int64 slices with no network, process, file, environment, or dynamic execution risks.
flag_int_slice.go safe No malicious patterns detected
flag_path.go safe No malicious patterns detected
flag_string.go safe No malicious patterns detected; the code is standard Go CLI flag handling with no exfiltration, credential harvesting, obfuscation, or process spawning.
flag_string_slice.go safe No malicious patterns detected; the code is a standard CLI flag implementation for handling string slices.
flag_timestamp.go safe No malicious patterns detected; this is a standard CLI timestamp flag implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
flag_uint.go safe No malicious patterns detected; the code is a standard CLI flag implementation for parsing unsigned integers from flags and environment variables without any exfiltration, code execution, or other suspicious behavior.
flag_uint64.go safe No malicious patterns detected; the code is a standard CLI flag implementation with no exfiltration, obfuscation, or suspicious behavior.
flag_uint64_slice.go safe No malicious patterns detected
flag_uint_slice.go safe No malicious patterns detected; the code implements a standard CLI flag type for uint slices with parsing, serialization, and environment variable support, with no exfiltration, credential harvesting, obfuscation, or other red flags.
funcs.go safe Cleared by Jev triage; no further analysis needed
help.go safe No malicious patterns detected; this is standard Go CLI help rendering code.
internal/example-cli/example-cli.go safe Cleared by Jev triage; no further analysis needed
internal/example-hello-world/example-hello-world.go safe Cleared by Jev triage; no further analysis needed
parse.go safe Cleared by Jev triage; no further analysis needed
sliceflag.go safe Cleared by Jev triage; no further analysis needed
sort.go safe Cleared by Jev triage; no further analysis needed
suggestions.go safe The code is a legitimate CLI suggestion utility using the smetrics library for string similarity; no malicious patterns, network calls, credential theft, or dynamic execution were found.
template.go safe No malicious patterns detected; the file contains Go text/template definitions for CLI help output with no execution, network, or filesystem activity.
zz_generated.flags.go safe No malicious patterns detected

Frequently asked questions

Is github.com/urfave/cli/v2 safe to use?

No confirmed malware was found in github.com/urfave/cli/v2@v2.27.7, but the review flagged 5 medium, 10 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/urfave/cli/v2 contain malware?

No malware was identified in github.com/urfave/cli/v2@v2.27.7 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/urfave/cli/v2 checked?

Togoder Security downloaded the published Go package and had an AI model read its 47 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/urfave/cli/v2 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/urfave/cli/v2@v2.27.7, cost nothing.

Related security reports