# @scalar/openapi-parser@0.29.7 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:04.000Z
- Files reviewed: 49
- Findings: 5 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@scalar/openapi-parser
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @scalar/openapi-parser@0.29.7 on Oct 6, 2026. An AI review of 49 source files produced 5 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] SSRF / unrestricted URL fetching

Finding ID: `NPS-7B63F8FFD1DC`

File: `dist/plugins/fetch-urls/fetch-urls.js`

The fetchUrls plugin accepts any string beginning with 'http://' or 'https://' and performs an HTTP request to it without validating the destination host. This allows fetching of internal/private network resources (e.g., http://169.254.169.254/, http://localhost, internal IPs), which is a classic SSRF vector. There is no allowlist, denylist, or DNS rebinding protection.

### [medium] Suspicious network request / potential data exfiltration vector

Finding ID: `NPS-A0291A436529`

File: `dist/plugins/fetch-urls/fetch-urls.js`

The get() method returns the full response body as text, which could be used by a caller (or the plugin itself if misused) to retrieve and exfiltrate arbitrary content from external or internal endpoints. The plugin also supports an attacker-influenced configuration.fetch override, meaning caller-supplied code can be invoked for any URL passed to get().

### [medium] Overridable fetch implementation (code execution via configuration)

Finding ID: `NPS-5BCC0C7A52C8`

File: `dist/plugins/fetch-urls/fetch-urls.js`

configuration.fetch is invoked as function call for arbitrary URLs. If an attacker can influence customConfiguration.fetch, they can execute arbitrary network calls or code paths. This is a design risk in plugin-style loaders where configuration may come from untrusted sources.

### [medium] Arbitrary file read

Finding ID: `NPS-BB4AE3B1D65E`

File: `dist/plugins/read-files/read-files.js:43`

The 'get' and 'resolvePath' methods perform unrestricted filesystem reads using user-supplied paths. The only validation in 'check' prevents URLs, newlines, JSON, and YAML, but does not prevent path traversal (e.g. '../../../etc/passwd') or reading sensitive files if the value is attacker-controlled. This could lead to information disclosure of sensitive files accessible to the process.

### [medium] Path traversal

Finding ID: `NPS-5ACD0172167A`

File: `dist/plugins/read-files/read-files.js:57`

The 'resolvePath' function joins a user-provided 'reference' to the directory of 'value' without sanitization, allowing traversal outside the intended directory. Combined with 'get', this can read arbitrary files.

### [low] Official typo / ambiguous limit check

Finding ID: `NPS-5DBE58248C2D`

File: `dist/plugins/fetch-urls/fetch-urls.js`

The limit check uses 'configuration?.limit !== false && numberOfRequests >= configuration?.limit'. If limit is a non-number string or otherwise truthy-but-not-numeric, comparison semantics are unclear. The console.warn message also contains a typo ('reeached'). Not malicious, but could lead to inconsistent request gating.

## Files reviewed

- `dist/plugins/fetch-urls/fetch-urls.js` (medium): This module is not overtly malicious (no exfiltration, obfuscation, credential harvesting, or process spawning), but it implements an unrestricted HTTP fetcher that enables SSRF and arbitrary outbound requests, and it allows a caller-provided fetch implementation to run for attacker-controlled URLs, which warrants a warning.
- `dist/plugins/read-files/read-files.js` (medium): Utility for reading local files allows unrestricted filesystem reads and path traversal, posing an information disclosure risk if input is attacker-controlled.
- `dist/configuration/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/plugins/fetch-urls/index.js` (safe): No malicious patterns detected
- `dist/plugins/read-files/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/types/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/dereference.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/details.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/get-entrypoint.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/get-list-of-references.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/get-segments-from-path.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/is-filesystem.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/is-json.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/is-yaml.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/join/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/join/join.js` (safe): No malicious patterns detected
- `dist/utils/load/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/load/load.js` (safe): No malicious patterns detected; the code performs OpenAPI document loading with pluggable resolvers and external reference handling, but contains no data exfiltration, credential harvesting, obfuscation, code execution, or other suspicious behavior.
- `dist/utils/make-filesystem.js` (safe): No malicious patterns detected
- `dist/utils/normalize.js` (safe): No malicious patterns detected; the code only performs YAML/JSON parsing and object normalization without any exfiltration, dynamic execution, or filesystem access.
- `dist/utils/openapi/actions/details.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/actions/files.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/actions/get.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/actions/toJson.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/actions/toYaml.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/commands/dereferenceCommand.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/commands/filterCommand.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/commands/loadCommand.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/commands/upgradeCommand.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/commands/validateCommand.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/openapi.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/openapi.test-d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/utils/queueTask.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/openapi/utils/workThroughQueue.js` (safe): No malicious patterns detected; the code is a legitimate task queue processor for OpenAPI utilities with no exfiltration, obfuscation, or dangerous operations.
- `dist/utils/resolve-references.js` (safe): No malicious patterns detected; the code is a legitimate OpenAPI reference resolver with no network, filesystem, process execution, or credential-harvesting behavior.
- `dist/utils/to-json.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/to-yaml.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/sanitize.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/utils/addInfoObject.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/utils/addLatestOpenApiVersion.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/utils/addMissingTags.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/utils/normalizeSecuritySchemes.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/transform/utils/rejectSwaggerDocuments.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/traverse.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/unescape-json-pointer.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/upgrade.js` (safe): No malicious patterns detected; the code performs a straightforward OpenAPI upgrade using imported utilities without any suspicious behavior.
- `dist/utils/validate.js` (safe): No malicious patterns detected; the code is a standard OpenAPI document validator with no network, filesystem, process, or dynamic code execution concerns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
