# github.com/yuin/goldmark@v1.8.6 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:16.000Z
- Files reviewed: 58
- Findings: 5 medium, 10 low severity findings
- Report: https://security.togoder.click/go/github.com/yuin/goldmark
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/yuin/goldmark@v1.8.6 on Oct 5, 2026. An AI review of 58 source files produced 5 medium, 10 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsafe HTML rendering configuration

Finding ID: `NPS-21D00D70F2E2`

File: `_benchmark/cmark/goldmark_benchmark.go:44`

The benchmark enables goldmark's html.WithUnsafe() option, which permits raw HTML and potentially dangerous content to pass through the renderer. While this is a benchmark file and not executed during package installation/import, using WithUnsafe() in any context that processes untrusted markdown can lead to XSS or HTML injection. It is a deliberate weakening of safety for the purpose of benchmarking, but still poses a risk if copied or reused.

### [medium] insecure network request

Finding ID: `NPS-91AD65D4950E`

File: `_tools/gen-unicode-case-folding-map.go:51`

Fetches CaseFolding.txt over plain HTTP (http://www.unicode.org/...) instead of HTTPS, allowing a network attacker to tamper with the data used to generate Go source code. This could enable supply-chain injection into generated mappings.

### [medium] lack of integrity verification

Finding ID: `NPS-214DEEE10635`

File: `_tools/gen-unicode-case-folding-map.go:51`

Downloaded Unicode data is parsed and embedded without any checksum, signature, or hash verification. If the endpoint or transport is compromised, arbitrary malicious mapping data could be embedded into generated code.

### [medium] Use of unsafe package

Finding ID: `NPS-82B4D46FC627`

File: `util/util_unsafe_go121.go`

The code uses unsafe.String and unsafe.Slice to create zero-copy conversions between byte slices and strings. This bypasses Go's type safety and can lead to memory corruption if the resulting read-only string is mutated (e.g., by unsafe.StringData) or if the byte slice backing a read-only string is modified. While not inherently malicious, it is a high-risk pattern that can introduce undefined behavior and security vulnerabilities.

### [medium] Mutability of read-only data

Finding ID: `NPS-96DB83F24E61`

File: `util/util_unsafe_go121.go`

BytesToReadOnlyString returns a string sharing the same memory as the input byte slice. If the caller modifies the original byte slice, the seemingly immutable string will change, potentially causing data races or unexpected behavior. Similarly, StringToReadOnlyBytes returns a byte slice that aliases the string's memory; writing to it is undefined behavior and can crash the program or corrupt memory.

### [low] Potential file creation outside package scope

Finding ID: `NPS-314ED2565D7E`

File: `_benchmark/cmark/goldmark_benchmark.go:26`

The program accepts a third command-line argument and creates a file at that path using os.Create. If run with an attacker-controlled argument or in an automated context, it could write arbitrary files. However, this is a benchmark utility intended for manual execution and does not run at install or import time.

### [low] Debug panic on I/O error

Finding ID: `NPS-8789912C6E65`

File: `_tools/gen-emb-structs.go:57`

os.ReadFile and json.Unmarshal errors call panic(err), which can crash the process and possibly leak stack traces/paths. Minor robustness concern rather than a malicious pattern.

### [low] Path traversal / arbitrary file write

Finding ID: `NPS-48BA82D1E50A`

File: `_tools/gen-emb-structs.go:62`

The tool takes an output path via the -o flag and writes generated content to it using os.Create without validation. If invoked on attacker-controlled arguments it can overwrite arbitrary files the process has permission to write. As a _tools generator this is expected behavior, but it is a security-relevant capability.

### [low] Unchecked type assertions leading to panic

Finding ID: `NPS-200408AA4321`

File: `_tools/gen-emb-structs.go:80`

The code performs unchecked type assertions on parsed JSON data (e.g. source["prefix"].(string), source["types"].(map[string]any), source["data"].([]any), d[prop].(string)). Malformed input will panic rather than fail gracefully, which can be abused for denial of service if the tool is run on untrusted input.

### [low] unbounded remote resource consumption

Finding ID: `NPS-E73766F81690`

File: `_tools/gen-unicode-case-folding-map.go:60`

The entire HTTP response body is read via io.ReadAll without any size limit or timeout, so a malicious or misbehaving server could cause excessive memory usage or indefinite hangs.

### [low] file write based on user input

Finding ID: `NPS-9443FC134BAB`

File: `_tools/gen-unicode-case-folding-map.go:126`

Writes generated JSON to an arbitrary path supplied via the -o flag with mode 0644. While this is normal CLI tool behavior, it does allow overwriting any file writable by the invoking user when the tool is run.

### [low] Potential XSS via Unsafe option

Finding ID: `NPS-B8EBF8A57513`

File: `renderer/html/html.go:243`

The renderer supports an 'Unsafe' mode (via WithUnsafe / optUnsafe) that renders raw HTML and potentially dangerous links as-is. When enabled, renderHTMLBlock, renderRawHTML, renderAutoLink, renderLink, and renderImage will pass through untrusted HTML and URLs without sanitization. This is an intentional, documented feature (default is safe/false), but enabling it with untrusted input enables XSS.

### [low] Attribute name injection

Finding ID: `NPS-4CBE2FFC4758`

File: `renderer/html/html.go:596`

In RenderAttributes, attribute names (attr.Name) are written directly to the output without validation or escaping. Attribute values are HTML-escaped via util.EscapeHTML, but names are not. If an AST is constructed programmatically with attacker-controlled attribute names, this could allow attribute injection. In normal markdown parsing, attribute names are constrained by the filter sets and ComeFrom parsing, so exploitability is limited.

### [low] unsafe pointer usage

Finding ID: `NPS-2C61DD5C991A`

File: `util/util_unsafe_go120.go:12`

The code uses the unsafe package to reinterpret memory between []byte and string types via unsafe.Pointer. While this is a common Go idiom for zero-copy conversion inherited from standard library patterns, StringToReadOnlyBytes produces a []byte that aliases the string's immutable backing memory. If callers write to the returned slice, it can cause undefined behavior, memory corruption, or crashes. This is not malicious but is unsafe by design.

### [low] unsafe pointer usage

Finding ID: `NPS-6068B656582C`

File: `util/util_unsafe_go120.go:17`

StringToReadOnlyBytes manually constructs reflect.SliceHeader fields (Data, Cap, Len) pointing into a string's memory. reflect.SliceHeader/StringHeader usage via unsafe.Pointer is fragile and deprecated in favor of unsafe.Slice/unsafe.String. Misuse by consumers (e.g., mutating the returned bytes) can lead to memory corruption. No malicious behavior (no network, exec, file, or credential access) is present.

## Files reviewed

- `_benchmark/cmark/goldmark_benchmark.go` (medium): The file is a benchmarking utility with no malicious behavior; it only exhibits a deliberate unsafe HTML renderer setting and a command-line file creation path, posing low-to-medium risk if misused.
- `_tools/gen-emb-structs.go` (medium): This is a straightforward code-generation utility with no network, exec, credential, or obfuscation behavior; only minor file-write and input-validation concerns typical of a build tool.
- `_tools/gen-unicode-case-folding-map.go` (medium): The tool is a developer code-generation utility with no evident exfiltration, credential harvesting, obfuscation, or backdoor behavior, but it uses insecure HTTP, lacks integrity verification of downloaded data, and has an unbounded read and arbitrary-path file write that could be abused in a supply-chain scenario.
- `util/util_unsafe_go120.go` (medium): The file contains only standard unsafe zero-copy byte/string conversion helpers with no malicious behavior, though the unsafe pointer aliasing carries inherent memory-safety risk if misused by callers.
- `util/util_unsafe_go121.go` (medium): The code uses unsafe pointer casting to create zero-copy byte/string conversions, which can introduce memory safety issues but shows no malicious intent.
- `_tools/gen-oss-fuzz-corpus.go` (safe): The code is a benign tool that reads a JSON spec file and packages example markdown files into a zip archive without any malicious behavior.
- `_tools/main.go` (safe): No malicious patterns detected
- `ast/ast.go` (safe): Cleared by Jev triage; no further analysis needed
- `ast/block.go` (safe): No malicious patterns detected; this is standard Goldmark Markdown AST node definitions with no network, filesystem, process execution, or obfuscation behavior.
- `ast/inline.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/ast/definition_list.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/ast/footnote.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/ast/strikethrough.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/ast/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/ast/tasklist.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/cjk.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/definition_list.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/footnote.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/gfm.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/linkify.go` (safe): No malicious patterns detected; the code is a standard Goldmark Markdown extension for auto-linking URLs, emails, and www domains with no network, filesystem, process execution, credential access, or obfuscation.
- `extension/package.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/strikethrough.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/table.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/tasklist.go` (safe): Cleared by Jev triage; no further analysis needed
- `extension/typographer.go` (safe): Cleared by Jev triage; no further analysis needed
- `markdown.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/attribute.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/atx_heading.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/auto_link.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/blockquote.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/code_block.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/code_span.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/delimiter.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/emphasis.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/fcode_block.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/html_block.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/link.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/link_ref.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/list.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/list_item.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/paragraph.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/parser.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/raw_html.go` (safe): No malicious patterns detected
- `parser/setext_headings.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser/thematic_break.go` (safe): Cleared by Jev triage; no further analysis needed
- `renderer/html/html.go` (safe): This is the legitimate goldmark HTML renderer; no exfiltration, credential harvesting, shell/process execution, dynamic code execution, or install-time payloads were found, though the documented Unsafe mode and unescaped attribute names warrant awareness.
- `renderer/renderer.go` (safe): Cleared by Jev triage; no further analysis needed
- `testutil/testutil.go` (safe): Cleared by Jev triage; no further analysis needed
- `text/package.go` (safe): Cleared by Jev triage; no further analysis needed
- `text/reader.go` (safe): Cleared by Jev triage; no further analysis needed
- `text/segment.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/html5entities.gen.go` (safe): This generated Go file contains only static HTML5 entity lookup tables and character/codepoint data with no executable logic, network, filesystem, or process operations.
- `util/html5entities.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/unicode_case_folding.gen.go` (safe): This is a generated Unicode case-folding data table containing only static rune arrays with no executable logic, network access, file I/O, or obfuscation.
- `util/unicode_case_folding.go` (safe): No malicious patterns detected in the Unicode case folding initialization code; it only populates an in-memory map from static data at package load time.
- `util/util.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/util_cjk.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/util_safe.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
