# @semantic-release/release-notes-generator@14.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:22.000Z
- Files reviewed: 4
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@semantic-release/release-notes-generator
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @semantic-release/release-notes-generator@14.1.0 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with user-controlled input

Finding ID: `NPS-4084E2DBB6D7`

File: `lib/load-changelog-config.js:27`

The code dynamically imports npm packages based on user-supplied `preset` or `config` values. While `import-from-esm` is used to resolve modules relative to the package or cwd, an attacker who controls the plugin configuration could load an arbitrary npm package, which is a legitimate but potentially risky feature common to semantic-release plugins.

### [medium] Dynamic module loading with user-controlled input

Finding ID: `NPS-0B063AC6F374`

File: `lib/load-changelog-config.js:29`

The `config` parameter is passed directly to `importFrom.silent` and `importFrom`, allowing arbitrary module names to be resolved and executed. This enables loading any installed npm package as a changelog configuration, which is the documented purpose but still represents a code execution vector if configuration is untrusted.

### [low] Code execution via imported modules

Finding ID: `NPS-1E53FAFDBAB7`

File: `lib/load-changelog-config.js:27`

The loaded configuration module is invoked as a function (`(await importFrom...)(presetConfig)` and `(...)()`), executing arbitrary code from the resolved module. This is expected behavior for conventional-changelog presets but executes third-party code at runtime.

## Files reviewed

- `lib/load-changelog-config.js` (medium): The code is a standard semantic-release changelog config loader that dynamically imports user-specified npm packages, which is intentional functionality but introduces a code execution surface if configuration input is untrusted; no overt malicious patterns such as exfiltration, credential harvesting, or shell spawning were found.
- `index.js` (safe): No malicious patterns detected; the code appears to be a legitimate semantic-release plugin for generating changelogs.
- `lib/hosts-config.js` (safe): Cleared by Jev triage; no further analysis needed
- `wrappers/conventional-changelog-writer.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
