Togoder security

Go package security report

github.com/yuin/goldmark Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v1.8.6 Files reviewed 58 Size 457.4 KB Scanned

Summary

Togoder Security scanned the Go package github.com/yuin/goldmark@v1.8.6 on Oct 5, 2026. An AI review of 58 source files produced 5 medium, 10 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
10
low

Findings 15

medium

Unsafe HTML rendering configuration

NPS-21D00D70F2E2

The benchmark enables goldmark's html.WithUnsafe() option, which permits raw HTML and potentially dangerous content to pass through the renderer. While this is a benchmark file and not executed during package installation/import, using WithUnsafe() in any context that processes untrusted markdown can lead to XSS or HTML injection. It is a deliberate weakening of safety for the purpose of benchmarking, but still poses a risk if copied or reused.

_benchmark/cmark/goldmark_benchmark.go:44
medium

insecure network request

NPS-91AD65D4950E

Fetches CaseFolding.txt over plain HTTP (http://www.unicode.org/...) instead of HTTPS, allowing a network attacker to tamper with the data used to generate Go source code. This could enable supply-chain injection into generated mappings.

_tools/gen-unicode-case-folding-map.go:51
medium

lack of integrity verification

NPS-214DEEE10635

Downloaded Unicode data is parsed and embedded without any checksum, signature, or hash verification. If the endpoint or transport is compromised, arbitrary malicious mapping data could be embedded into generated code.

_tools/gen-unicode-case-folding-map.go:51
medium

Use of unsafe package

NPS-82B4D46FC627

The code uses unsafe.String and unsafe.Slice to create zero-copy conversions between byte slices and strings. This bypasses Go's type safety and can lead to memory corruption if the resulting read-only string is mutated (e.g., by unsafe.StringData) or if the byte slice backing a read-only string is modified. While not inherently malicious, it is a high-risk pattern that can introduce undefined behavior and security vulnerabilities.

util/util_unsafe_go121.go
medium

Mutability of read-only data

NPS-96DB83F24E61

BytesToReadOnlyString returns a string sharing the same memory as the input byte slice. If the caller modifies the original byte slice, the seemingly immutable string will change, potentially causing data races or unexpected behavior. Similarly, StringToReadOnlyBytes returns a byte slice that aliases the string's memory; writing to it is undefined behavior and can crash the program or corrupt memory.

util/util_unsafe_go121.go
low

Potential file creation outside package scope

NPS-314ED2565D7E

The program accepts a third command-line argument and creates a file at that path using os.Create. If run with an attacker-controlled argument or in an automated context, it could write arbitrary files. However, this is a benchmark utility intended for manual execution and does not run at install or import time.

_benchmark/cmark/goldmark_benchmark.go:26
low

Debug panic on I/O error

NPS-8789912C6E65

os.ReadFile and json.Unmarshal errors call panic(err), which can crash the process and possibly leak stack traces/paths. Minor robustness concern rather than a malicious pattern.

_tools/gen-emb-structs.go:57
low

Path traversal / arbitrary file write

NPS-48BA82D1E50A

The tool takes an output path via the -o flag and writes generated content to it using os.Create without validation. If invoked on attacker-controlled arguments it can overwrite arbitrary files the process has permission to write. As a _tools generator this is expected behavior, but it is a security-relevant capability.

_tools/gen-emb-structs.go:62
low

Unchecked type assertions leading to panic

NPS-200408AA4321

The code performs unchecked type assertions on parsed JSON data (e.g. source["prefix"].(string), source["types"].(map[string]any), source["data"].([]any), d[prop].(string)). Malformed input will panic rather than fail gracefully, which can be abused for denial of service if the tool is run on untrusted input.

_tools/gen-emb-structs.go:80
low

unbounded remote resource consumption

NPS-E73766F81690

The entire HTTP response body is read via io.ReadAll without any size limit or timeout, so a malicious or misbehaving server could cause excessive memory usage or indefinite hangs.

_tools/gen-unicode-case-folding-map.go:60
low

file write based on user input

NPS-9443FC134BAB

Writes generated JSON to an arbitrary path supplied via the -o flag with mode 0644. While this is normal CLI tool behavior, it does allow overwriting any file writable by the invoking user when the tool is run.

_tools/gen-unicode-case-folding-map.go:126
low

Potential XSS via Unsafe option

NPS-B8EBF8A57513

The renderer supports an 'Unsafe' mode (via WithUnsafe / optUnsafe) that renders raw HTML and potentially dangerous links as-is. When enabled, renderHTMLBlock, renderRawHTML, renderAutoLink, renderLink, and renderImage will pass through untrusted HTML and URLs without sanitization. This is an intentional, documented feature (default is safe/false), but enabling it with untrusted input enables XSS.

renderer/html/html.go:243
low

Attribute name injection

NPS-4CBE2FFC4758

In RenderAttributes, attribute names (attr.Name) are written directly to the output without validation or escaping. Attribute values are HTML-escaped via util.EscapeHTML, but names are not. If an AST is constructed programmatically with attacker-controlled attribute names, this could allow attribute injection. In normal markdown parsing, attribute names are constrained by the filter sets and ComeFrom parsing, so exploitability is limited.

renderer/html/html.go:596
low

unsafe pointer usage

NPS-2C61DD5C991A

The code uses the unsafe package to reinterpret memory between []byte and string types via unsafe.Pointer. While this is a common Go idiom for zero-copy conversion inherited from standard library patterns, StringToReadOnlyBytes produces a []byte that aliases the string's immutable backing memory. If callers write to the returned slice, it can cause undefined behavior, memory corruption, or crashes. This is not malicious but is unsafe by design.

util/util_unsafe_go120.go:12
low

unsafe pointer usage

NPS-6068B656582C

StringToReadOnlyBytes manually constructs reflect.SliceHeader fields (Data, Cap, Len) pointing into a string's memory. reflect.SliceHeader/StringHeader usage via unsafe.Pointer is fragile and deprecated in favor of unsafe.Slice/unsafe.String. Misuse by consumers (e.g., mutating the returned bytes) can lead to memory corruption. No malicious behavior (no network, exec, file, or credential access) is present.

util/util_unsafe_go120.go:17

Files reviewed

FileVerdictWhat the reviewer saw
_benchmark/cmark/goldmark_benchmark.go medium The file is a benchmarking utility with no malicious behavior; it only exhibits a deliberate unsafe HTML renderer setting and a command-line file creation path, posing low-to-medium risk if misused.
_tools/gen-emb-structs.go medium This is a straightforward code-generation utility with no network, exec, credential, or obfuscation behavior; only minor file-write and input-validation concerns typical of a build tool.
_tools/gen-unicode-case-folding-map.go medium The tool is a developer code-generation utility with no evident exfiltration, credential harvesting, obfuscation, or backdoor behavior, but it uses insecure HTTP, lacks integrity verification of downloaded data, and has an unbounded read and arbitrary-path file write that could be abused in a supply-chain scenario.
util/util_unsafe_go120.go medium The file contains only standard unsafe zero-copy byte/string conversion helpers with no malicious behavior, though the unsafe pointer aliasing carries inherent memory-safety risk if misused by callers.
util/util_unsafe_go121.go medium The code uses unsafe pointer casting to create zero-copy byte/string conversions, which can introduce memory safety issues but shows no malicious intent.
_tools/gen-oss-fuzz-corpus.go safe The code is a benign tool that reads a JSON spec file and packages example markdown files into a zip archive without any malicious behavior.
_tools/main.go safe No malicious patterns detected
ast/ast.go safe Cleared by Jev triage; no further analysis needed
ast/block.go safe No malicious patterns detected; this is standard Goldmark Markdown AST node definitions with no network, filesystem, process execution, or obfuscation behavior.
ast/inline.go safe Cleared by Jev triage; no further analysis needed
extension/ast/definition_list.go safe Cleared by Jev triage; no further analysis needed
extension/ast/footnote.go safe Cleared by Jev triage; no further analysis needed
extension/ast/strikethrough.go safe Cleared by Jev triage; no further analysis needed
extension/ast/table.go safe Cleared by Jev triage; no further analysis needed
extension/ast/tasklist.go safe Cleared by Jev triage; no further analysis needed
extension/cjk.go safe Cleared by Jev triage; no further analysis needed
extension/definition_list.go safe Cleared by Jev triage; no further analysis needed
extension/footnote.go safe Cleared by Jev triage; no further analysis needed
extension/gfm.go safe Cleared by Jev triage; no further analysis needed
extension/linkify.go safe No malicious patterns detected; the code is a standard Goldmark Markdown extension for auto-linking URLs, emails, and www domains with no network, filesystem, process execution, credential access, or obfuscation.
extension/package.go safe Cleared by Jev triage; no further analysis needed
extension/strikethrough.go safe Cleared by Jev triage; no further analysis needed
extension/table.go safe Cleared by Jev triage; no further analysis needed
extension/tasklist.go safe Cleared by Jev triage; no further analysis needed
extension/typographer.go safe Cleared by Jev triage; no further analysis needed
Show 33 more files
FileVerdictWhat the reviewer saw
markdown.go safe Cleared by Jev triage; no further analysis needed
parser/attribute.go safe Cleared by Jev triage; no further analysis needed
parser/atx_heading.go safe Cleared by Jev triage; no further analysis needed
parser/auto_link.go safe Cleared by Jev triage; no further analysis needed
parser/blockquote.go safe Cleared by Jev triage; no further analysis needed
parser/code_block.go safe Cleared by Jev triage; no further analysis needed
parser/code_span.go safe Cleared by Jev triage; no further analysis needed
parser/delimiter.go safe Cleared by Jev triage; no further analysis needed
parser/emphasis.go safe Cleared by Jev triage; no further analysis needed
parser/fcode_block.go safe Cleared by Jev triage; no further analysis needed
parser/html_block.go safe Cleared by Jev triage; no further analysis needed
parser/link.go safe Cleared by Jev triage; no further analysis needed
parser/link_ref.go safe Cleared by Jev triage; no further analysis needed
parser/list.go safe Cleared by Jev triage; no further analysis needed
parser/list_item.go safe Cleared by Jev triage; no further analysis needed
parser/paragraph.go safe Cleared by Jev triage; no further analysis needed
parser/parser.go safe Cleared by Jev triage; no further analysis needed
parser/raw_html.go safe No malicious patterns detected
parser/setext_headings.go safe Cleared by Jev triage; no further analysis needed
parser/thematic_break.go safe Cleared by Jev triage; no further analysis needed
renderer/html/html.go safe This is the legitimate goldmark HTML renderer; no exfiltration, credential harvesting, shell/process execution, dynamic code execution, or install-time payloads were found, though the documented Unsafe mode and unescaped attribute names warrant awareness.
renderer/renderer.go safe Cleared by Jev triage; no further analysis needed
testutil/testutil.go safe Cleared by Jev triage; no further analysis needed
text/package.go safe Cleared by Jev triage; no further analysis needed
text/reader.go safe Cleared by Jev triage; no further analysis needed
text/segment.go safe Cleared by Jev triage; no further analysis needed
util/html5entities.gen.go safe This generated Go file contains only static HTML5 entity lookup tables and character/codepoint data with no executable logic, network, filesystem, or process operations.
util/html5entities.go safe Cleared by Jev triage; no further analysis needed
util/unicode_case_folding.gen.go safe This is a generated Unicode case-folding data table containing only static rune arrays with no executable logic, network access, file I/O, or obfuscation.
util/unicode_case_folding.go safe No malicious patterns detected in the Unicode case folding initialization code; it only populates an in-memory map from static data at package load time.
util/util.go safe Cleared by Jev triage; no further analysis needed
util/util_cjk.go safe Cleared by Jev triage; no further analysis needed
util/util_safe.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/yuin/goldmark

VersionVerdictFilesScanned
v1.8.6 Needs review 58 Oct 5, 2026

Frequently asked questions

Is github.com/yuin/goldmark safe to use?

No confirmed malware was found in github.com/yuin/goldmark@v1.8.6, but the review flagged 5 medium, 10 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/yuin/goldmark contain malware?

No malware was identified in github.com/yuin/goldmark@v1.8.6 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/yuin/goldmark checked?

Togoder Security downloaded the published Go package and had an AI model read its 58 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/yuin/goldmark together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/yuin/goldmark@v1.8.6, cost nothing.

Related security reports