# github.com/volatiletech/sqlboiler@v3.7.1+incompatible security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:54.000Z
- Files reviewed: 68
- Findings: 10 medium, 14 low severity findings
- Report: https://security.togoder.click/go/github.com/volatiletech/sqlboiler
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/volatiletech/sqlboiler@v3.7.1+incompatible on Oct 5, 2026. An AI review of 68 source files produced 10 medium, 14 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic file loading / template injection

Finding ID: `NPS-23FE9804260B`

File: `boilingcore/boilingcore.go:261`

initTemplates allows loading arbitrary template files from user-supplied TemplateDirs, and Replacements can replace any existing template with an arbitrary file path. This could allow execution of attacker-controlled templates if config is untrusted.

### [medium] Potential path traversal / absolute path usage

Finding ID: `NPS-7C11C7DA2800`

File: `boilingcore/boilingcore.go:391`

findTemplates walks arbitrary root paths from TemplateDirs using filepath.Walk and filepath.Abs. Combined with Replacements loading fileLoader(replacement) directly, files outside the intended package scope may be read and executed as templates.

### [medium] File system manipulation

Finding ID: `NPS-A1A13D94939C`

File: `boilingcore/boilingcore.go:565`

initOutFolders calls os.RemoveAll on s.Config.OutFolder when Config.Wipe is true. If OutFolder is attacker-controlled or misconfigured (e.g., '/', '~'), this could wipe arbitrary directories.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-4892AEB8C839`

File: `boilingcore/output.go:231`

The writeFile function writes generated code to a directory specified by state.Config.OutFolder without validating or sandboxing the path. If OutFolder is ever derived from untrusted input (e.g., a config file controlled by an attacker), this could allow arbitrary file write with 0664 permissions. While typical usage is benign code generation, the lack of path validation poses a potential risk.

### [medium] Sensitive file overwrite potential

Finding ID: `NPS-4EE5AA24C22A`

File: `boilingcore/output.go:232`

writeFile uses filepath.Join(outFolder, fileName) and writes with 0664 permissions without checking whether the resolved path escapes the intended output directory (e.g., via '..' components in fileName or absolute paths). If fileName is influenced by template names, an attacker-controlled template could overwrite arbitrary files.

### [medium] Dynamic template parsing

Finding ID: `NPS-EC97196ACA2E`

File: `boilingcore/templates.go:145`

loadTemplates parses template content from multiple sources (file, base64, asset). Templates are parsed with text/template which, while generally safe from code execution, could enable template injection if template content is attacker-controlled, potentially leading to information disclosure via template function access.

### [medium] File system read via ioutil.ReadFile

Finding ID: `NPS-945B12746295`

File: `boilingcore/templates.go:161`

The fileLoader.Load() method reads arbitrary file paths passed via the template loader. If template paths are controlled by an attacker (e.g., through configuration or external input), this could allow reading sensitive files from the filesystem.

### [medium] Process Execution via os/exec

Finding ID: `NPS-B08954FDAA29`

File: `drivers/binary_driver.go:66`

The function `execute` calls `exec.Command(executable, method)` and runs external binaries whose paths come from the `binaryDriver` string type, which is provided by the package configuration. This is the intended design of the SQLBoiler binary driver plugin mechanism (loading external DB drivers as separate executables), but from a security review perspective it means the package will spawn arbitrary external binaries at runtime. If a malicious driver string is supplied via configuration, this results in arbitrary command execution on the host. There is no allowlist, path validation, or signature verification of the executable.

### [medium] Unvalidated Binary Path (no path restriction)

Finding ID: `NPS-3C04C27FA948`

File: `drivers/binary_driver.go:66`

The `executable` argument is used directly without any sanitization, path traversal checks, or confinement to a known trusted directory. A value such as `/bin/sh` or an absolute path to a downloaded payload could be executed. This is a design-level risk in the plugin loader.

### [medium] SQL Query Construction

Finding ID: `NPS-0B5029078679`

File: `queries/query.go`

The code constructs SQL queries from string arguments without any apparent validation or sanitization in this file. While the actual building of the query happens in BuildQuery (not shown), the public API allows passing arbitrary SQL clauses and raw SQL, which could lead to SQL injection if misused. This is a common design in ORMs and query builders, but it is a potential security risk if user input is passed directly.

### [low] Debug output of sensitive config

Finding ID: `NPS-9AFCBA27A4DE`

File: `boilingcore/boilingcore.go:90`

When Config.Debug is enabled, the entire Config (including DriverConfig which typically holds DB credentials) is serialized to JSON and printed to stdout via fmt.Printf. This can leak credentials to logs/CI output.

### [low] Global mutable buffer shared across goroutines

Finding ID: `NPS-F50824BB06FB`

File: `boilingcore/output.go:31`

templateByteBuffer is a package-level mutable *bytes.Buffer reused across all template executions. Although the code comments acknowledge this will be a concurrency issue, concurrent calls to executeTemplates or executeSingletonTemplates could lead to data races, corrupted output, and potentially mis-generated files. This is a robustness/security concern if the package is used in a concurrent context.

### [low] Panic in String method

Finding ID: `NPS-371949840C5B`

File: `boilingcore/templates.go:194`

base64Loader.String() panics on invalid base64 input. While not directly malicious, this could be used for denial-of-service if an attacker controls the base64 string.

### [low] Untrusted Input Passed to Child Process

Finding ID: `NPS-03D3982AB4F7`

File: `drivers/binary_driver.go:57`

User/driver configuration (`config Config`) is JSON-marshalled and piped to the child process's stdin. If the external binary is attacker-controlled or the config contains sensitive values (e.g. DB credentials), they are handed to whatever executable is specified. Combined with the lack of executable validation, this constitutes a potential credential/data exposure vector.

### [low] Untrusted input handling / missing bounds check

Finding ID: `NPS-F22EED16C74E`

File: `drivers/driver_main.go:11`

os.Args[1] is accessed directly without verifying len(os.Args) > 1, which would cause a panic if the binary is invoked with no arguments. More importantly, the 'method' value is used to select driver behavior; if the driver implementation is supplied by a third party and the dispatcher is generic, unexpected methods are silently ignored (output remains nil), which could mask errors.

### [low] Potential information disclosure via verbose error output

Finding ID: `NPS-78B1B3211410`

File: `drivers/driver_main.go:24`

When JSON parsing fails, the error handler prints the entire raw input buffer (b) to stderr. If the config contains secrets (tokens, credentials, environment-specific values), they could be leaked into logs or CI output. This is a minor concern for a driver helper but worth noting.

### [low] Configuration and environment variable harvesting

Finding ID: `NPS-FCCB0E5106D2`

File: `main.go:33`

initConfig reads user config from the working directory, $XDG_CONFIG_HOME/sqlboiler, or $HOME/.config/sqlboiler, and the code iterates os.Environ() in allKeys to pick up driver-prefixed environment variables. This is standard Viper configuration behavior, not exfiltration, but it does mean all env vars matching '<driver>.' are collected and passed into the driver config. No network transmission of this data is present in the analyzed file.

### [low] Wipe / destructive filesystem operation

Finding ID: `NPS-A89C3C75AA63`

File: `main.go:118`

The '--wipe' flag causes the output folder to be deleted (rm -rf) before generation. This is a deliberate, user-controlled feature, but it is a destructive filesystem operation that could delete unintended data if the user misconfigures the output path. Not malicious, but worth flagging for review.

### [low] Process execution / dynamic driver loading

Finding ID: `NPS-162C0F246A3B`

File: `main.go:168`

The preRun function uses exec.LookPath to resolve a driver binary named 'sqlboiler-<driver>' from the user-provided driver argument and then executes it (via boilingcore.New/State.Run). This is intentional functionality for a code generator, but the ability to load and execute arbitrary binaries whose names are influenced by command-line input constitutes a process-spawning surface. If the 'sqlboiler-' prefixed binary is present on PATH, it will be resolved and run, which is expected behavior for this tool but is still a notable execution vector.

### [low] Debug Information Exposure

Finding ID: `NPS-155C1BD27DB6`

File: `queries/query.go`

When DebugMode is enabled, the code writes the full SQL query and its arguments to a debug writer. This could expose sensitive data if debug logging is enabled in production.

### [low] weak randomness for UUID generation

Finding ID: `NPS-3C6631EB213F`

File: `randomize/random.go`

The uuid.NewV4() function is called in FormattedString for generating UUIDs, but this function may rely on math/rand instead of crypto/rand if the underlying library is configured that way. However, gofrs/uuid's NewV4 uses crypto/rand by default, so this is not a serious issue. More notably, the surrounding code uses a caller-supplied nextInt function for randomness, which is often based on math/rand, not cryptographically secure. This could lead to predictable test data if used in security-sensitive contexts, but the package is clearly intended for test data randomization, not cryptographic purposes.

### [low] debug print statement

Finding ID: `NPS-98DA0F3002C3`

File: `randomize/random.go`

The MediumUint function contains a fmt.Println(fieldType) call that prints the field type to stdout. This appears to be leftover debug code that could leak information or pollute output in production use. It is not malicious but is a code quality issue.

### [low] potential panic on error

Finding ID: `NPS-DC87E4C8FC86`

File: `randomize/random.go`

Functions like FormattedString panic on errors from EnumValue or uuid.NewV4. While panicking is not inherently malicious, it can cause denial of service if the input is untrusted. In a test data generation context this is less concerning.

### [low] md5 usage for seeding

Finding ID: `NPS-BC59F7EDE1CD`

File: `randomize/random.go`

StableDBName uses md5 to hash the input for seed generation. md5 is cryptographically broken but here it is used only for deterministic seed derivation in test database naming, not for security purposes. This is acceptable but worth noting.

## Files reviewed

- `boilingcore/boilingcore.go` (medium): No overt malware (no exfiltration, mining, or backdoors), but the code permits arbitrary template file loading, wiping of user-specified directories, and printing of DB credentials in debug mode, posing configuration-driven misuse risks.
- `boilingcore/output.go` (medium): The code is a benign SQL code generator but has potential path traversal/arbitrary file write risks and a data-race-prone global buffer that warrant caution.
- `boilingcore/templates.go` (medium): No overt malicious patterns detected, but the file loader allows reading arbitrary files and templates are dynamically parsed, which could be risky if inputs are attacker-controlled.
- `drivers/binary_driver.go` (medium): The code is an intentional plugin loader that spawns external driver binaries via os/exec with unvalidated, configuration-controlled executable paths, creating a latent arbitrary-command-execution and credential-exposure risk if driver names are not trusted.
- `drivers/driver_main.go` (medium): The file is a generic CLI dispatcher for driver plugins; it contains no exfiltration, credential harvesting, code execution, or network activity, but does leak raw stdin on JSON parse errors and lacks argument validation.
- `main.go` (medium): sqlboiler's main.go contains no obvious malicious payloads; it performs legitimate CLI, config loading, and driver-binary execution which are inherent to its function, though the driver execution and wipe features warrant awareness.
- `queries/query.go` (medium): The code is a legitimate SQL query builder with no obvious malicious patterns, but it allows raw SQL construction and debug logging that could pose risks if misused.
- `randomize/random.go` (medium): The code appears to be a legitimate test data randomization library for SQLBoiler, with no malicious patterns such as data exfiltration, credential harvesting, or backdoors; minor issues include debug print and use of non-cryptographic randomness.
- `boil/columns.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/context_keys.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/db.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/debug.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `boil/global.go` (safe): The file contains only standard global state management for database handles and timezone settings with no malicious patterns.
- `boil/hooks.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/aliases.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `boilingcore/text_helpers.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/column.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/config.go` (safe): No malicious patterns detected
- `drivers/interface.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/keys.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/mocks/mock.go` (safe): No malicious patterns detected
- `drivers/registration.go` (safe): No malicious patterns detected
- `drivers/relationships.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-mssql/driver/bindata.go` (safe): This is standard go-bindata generated code that embeds SQL template files as compressed assets; no malicious patterns, exfiltration, or dynamic execution were detected.
- `drivers/sqlboiler-mssql/driver/mssql.go` (safe): No malicious patterns detected
- `drivers/sqlboiler-mssql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-mysql/driver/bindata.go` (safe): This is a standard go-bindata generated file embedding template assets; it contains no malicious patterns, network activity, credential harvesting, or dynamic code execution.
- `drivers/sqlboiler-mysql/driver/mysql.go` (safe): No malicious patterns detected; the code is a legitimate MySQL driver for sqlboiler with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `drivers/sqlboiler-mysql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/sqlboiler-psql/driver/bindata.go` (safe): No malicious patterns detected; the file is standard go-bindata generated code that embeds gzip-compressed Go templates and provides read/restore helpers without network, credential, or command execution behavior.
- `drivers/sqlboiler-psql/driver/psql.go` (safe): No malicious patterns detected; the code is a legitimate SQLBoiler PostgreSQL driver that performs database introspection and type mapping.
- `drivers/sqlboiler-psql/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `drivers/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `importers/imports.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/eager_load.go` (safe): No malicious patterns detected; the code is a legitimate eager-loading implementation for the SQLBoiler ORM using reflection with no exfiltration, credential harvesting, obfuscation, network, or process-spawning behavior.
- `queries/helpers.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/qm/query_mods.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/qmhelper/qmhelper.go` (safe): Cleared by Jev triage; no further analysis needed
- `queries/query_builders.go` (safe): No malicious patterns detected; the code is a standard SQL query builder from the sqlboiler library with no network, environmental, or dynamic execution concerns.
- `queries/reflect.go` (safe): No malicious patterns detected
- `randomize/randomize.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/buf_pool.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/inflect.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/sets.go` (safe): Cleared by Jev triage; no further analysis needed
- `strmangle/strmangle.go` (safe): No malicious patterns detected
- `types/array.go` (safe): No malicious patterns detected; this is a legitimate PostgreSQL array type parser from the lib/pq/sqlboiler ecosystem with no network, credential, exec, or filesystem abuse.
- `types/byte.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/decimal.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/hstore.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/json.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/box.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/circle.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/general.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/line.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/lseg.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullBox.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullCircle.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullLine.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullLseg.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPath.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPoint.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/nullPolygon.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/path.go` (safe): No malicious patterns detected; the code implements PostgreSQL geometric Path type serialization/deserialization and randomization without any network, filesystem, process, or credential access.
- `types/pgeo/point.go` (safe): Cleared by Jev triage; no further analysis needed
- `types/pgeo/polygon.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
