Togoder security

npm package security report

@scalar/openapi-parser@0.29.7 security report

Risky patterns found that deserve a look.

Needs review Version 0.29.7 Files reviewed 49 Size 52.1 KB Scanned

Summary

Togoder Security scanned the npm package @scalar/openapi-parser@0.29.7 on Oct 6, 2026. An AI review of 49 source files produced 5 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
1
low

Findings 6

medium

SSRF / unrestricted URL fetching

NPS-7B63F8FFD1DC

The fetchUrls plugin accepts any string beginning with 'http://' or 'https://' and performs an HTTP request to it without validating the destination host. This allows fetching of internal/private network resources (e.g., http://169.254.169.254/, http://localhost, internal IPs), which is a classic SSRF vector. There is no allowlist, denylist, or DNS rebinding protection.

dist/plugins/fetch-urls/fetch-urls.js
medium

Suspicious network request / potential data exfiltration vector

NPS-A0291A436529

The get() method returns the full response body as text, which could be used by a caller (or the plugin itself if misused) to retrieve and exfiltrate arbitrary content from external or internal endpoints. The plugin also supports an attacker-influenced configuration.fetch override, meaning caller-supplied code can be invoked for any URL passed to get().

dist/plugins/fetch-urls/fetch-urls.js
medium

Overridable fetch implementation (code execution via configuration)

NPS-5BCC0C7A52C8

configuration.fetch is invoked as function call for arbitrary URLs. If an attacker can influence customConfiguration.fetch, they can execute arbitrary network calls or code paths. This is a design risk in plugin-style loaders where configuration may come from untrusted sources.

dist/plugins/fetch-urls/fetch-urls.js
medium

Arbitrary file read

NPS-BB4AE3B1D65E

The 'get' and 'resolvePath' methods perform unrestricted filesystem reads using user-supplied paths. The only validation in 'check' prevents URLs, newlines, JSON, and YAML, but does not prevent path traversal (e.g. '../../../etc/passwd') or reading sensitive files if the value is attacker-controlled. This could lead to information disclosure of sensitive files accessible to the process.

dist/plugins/read-files/read-files.js:43
medium

Path traversal

NPS-5ACD0172167A

The 'resolvePath' function joins a user-provided 'reference' to the directory of 'value' without sanitization, allowing traversal outside the intended directory. Combined with 'get', this can read arbitrary files.

dist/plugins/read-files/read-files.js:57
low

Official typo / ambiguous limit check

NPS-5DBE58248C2D

The limit check uses 'configuration?.limit !== false && numberOfRequests >= configuration?.limit'. If limit is a non-number string or otherwise truthy-but-not-numeric, comparison semantics are unclear. The console.warn message also contains a typo ('reeached'). Not malicious, but could lead to inconsistent request gating.

dist/plugins/fetch-urls/fetch-urls.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/plugins/fetch-urls/fetch-urls.js medium This module is not overtly malicious (no exfiltration, obfuscation, credential harvesting, or process spawning), but it implements an unrestricted HTTP fetcher that enables SSRF and arbitrary outbound requests, and it allows a caller-provided fetch implementation to run for attacker-controlled URLs, which warrants a warning.
dist/plugins/read-files/read-files.js medium Utility for reading local files allows unrestricted filesystem reads and path traversal, posing an information disclosure risk if input is attacker-controlled.
dist/configuration/index.js safe Cleared by Jev triage; no further analysis needed
dist/index.js safe Cleared by Jev triage; no further analysis needed
dist/plugins/fetch-urls/index.js safe No malicious patterns detected
dist/plugins/read-files/index.js safe Cleared by Jev triage; no further analysis needed
dist/types/index.js safe Cleared by Jev triage; no further analysis needed
dist/utils/dereference.js safe Cleared by Jev triage; no further analysis needed
dist/utils/details.js safe Cleared by Jev triage; no further analysis needed
dist/utils/filter.js safe Cleared by Jev triage; no further analysis needed
dist/utils/get-entrypoint.js safe Cleared by Jev triage; no further analysis needed
dist/utils/get-list-of-references.js safe Cleared by Jev triage; no further analysis needed
dist/utils/get-segments-from-path.js safe Cleared by Jev triage; no further analysis needed
dist/utils/is-filesystem.js safe Cleared by Jev triage; no further analysis needed
dist/utils/is-json.js safe Cleared by Jev triage; no further analysis needed
dist/utils/is-yaml.js safe Cleared by Jev triage; no further analysis needed
dist/utils/join/index.js safe Cleared by Jev triage; no further analysis needed
dist/utils/join/join.js safe No malicious patterns detected
dist/utils/load/index.js safe Cleared by Jev triage; no further analysis needed
dist/utils/load/load.js safe No malicious patterns detected; the code performs OpenAPI document loading with pluggable resolvers and external reference handling, but contains no data exfiltration, credential harvesting, obfuscation, code execution, or other suspicious behavior.
dist/utils/make-filesystem.js safe No malicious patterns detected
dist/utils/normalize.js safe No malicious patterns detected; the code only performs YAML/JSON parsing and object normalization without any exfiltration, dynamic execution, or filesystem access.
dist/utils/openapi/actions/details.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/actions/files.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/actions/get.js safe Cleared by Jev triage; no further analysis needed
Show 24 more files
FileVerdictWhat the reviewer saw
dist/utils/openapi/actions/toJson.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/actions/toYaml.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/commands/dereferenceCommand.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/commands/filterCommand.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/commands/loadCommand.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/commands/upgradeCommand.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/commands/validateCommand.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/openapi.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/openapi.test-d.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/utils/queueTask.js safe Cleared by Jev triage; no further analysis needed
dist/utils/openapi/utils/workThroughQueue.js safe No malicious patterns detected; the code is a legitimate task queue processor for OpenAPI utilities with no exfiltration, obfuscation, or dangerous operations.
dist/utils/resolve-references.js safe No malicious patterns detected; the code is a legitimate OpenAPI reference resolver with no network, filesystem, process execution, or credential-harvesting behavior.
dist/utils/to-json.js safe Cleared by Jev triage; no further analysis needed
dist/utils/to-yaml.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/sanitize.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/utils/addInfoObject.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/utils/addLatestOpenApiVersion.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/utils/addMissingTags.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/utils/normalizeSecuritySchemes.js safe Cleared by Jev triage; no further analysis needed
dist/utils/transform/utils/rejectSwaggerDocuments.js safe Cleared by Jev triage; no further analysis needed
dist/utils/traverse.js safe Cleared by Jev triage; no further analysis needed
dist/utils/unescape-json-pointer.js safe Cleared by Jev triage; no further analysis needed
dist/utils/upgrade.js safe No malicious patterns detected; the code performs a straightforward OpenAPI upgrade using imported utilities without any suspicious behavior.
dist/utils/validate.js safe No malicious patterns detected; the code is a standard OpenAPI document validator with no network, filesystem, process, or dynamic code execution concerns.

Frequently asked questions

Is @scalar/openapi-parser safe to use?

No confirmed malware was found in @scalar/openapi-parser@0.29.7, but the review flagged 5 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @scalar/openapi-parser contain malware?

No malware was identified in @scalar/openapi-parser@0.29.7 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @scalar/openapi-parser checked?

Togoder Security downloaded the published npm package and had an AI model read its 49 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @scalar/openapi-parser together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @scalar/openapi-parser@0.29.7, cost nothing.

Related security reports