# conventional-changelog-writer@8.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:15:01.000Z
- Files reviewed: 14
- Findings: 1 high, 5 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/conventional-changelog-writer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package conventional-changelog-writer@8.2.0 on Oct 6, 2026. An AI review of 14 source files produced 1 high, 5 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Dynamic code execution via file loading

Finding ID: `NPS-09427C2683D8`

File: `dist/cli/index.js:37`

The --options flag loads a JavaScript object from a user-supplied filepath via loadDataFile(optionsPath). If loadDataFile uses import(), require(), or eval(), this enables arbitrary code execution from a file whose path is controlled by the CLI user or an attacker who can influence arguments. The name 'options' and the meow help text ('a filepath of a javascript object') strongly suggest runtime code loading rather than pure JSON parsing.

### [medium] External module delegation

Finding ID: `NPS-EDFB8AD02869`

File: `dist/cli/index.js:3`

Core functionality (writeChangelog, loadDataFile, readCommitsFromFiles, readCommitsFromStdin) is imported from '../index.js' and './utils.js', which are not included in this file. The actual behavior of these functions—especially loadDataFile and writeChangelog—cannot be verified from this snippet and could contain the malicious logic described above.

### [medium] Dynamic code execution via file loading

Finding ID: `NPS-DE939873BE56`

File: `dist/cli/index.js:27`

The --context flag similarly loads data from a user-supplied filepath via loadDataFile(contextPath), which may execute JavaScript if the loader supports non-JSON formats or uses dynamic import/require.

### [medium] Dynamic import with external input

Finding ID: `NPS-55EEFD20AF22`

File: `dist/cli/utils.js:54`

The `loadDataFile` function dynamically imports a file path provided as input. While it uses `pathToFileURL` and `resolve` to convert to a file URL, the path is derived from user-supplied input (`filePath`). An attacker who controls this argument could potentially load arbitrary JavaScript modules from the file system, leading to code execution. The function is exported and might be called with untrusted data.

### [medium] Template injection risk via user-supplied partials

Finding ID: `NPS-152DF9A3B8B4`

File: `dist/template.js:59`

The `partials` option allows arbitrary Handlebars partials to be registered from external input. Combined with `noEscape: true`, malicious templates could execute helper logic or inject content. The `mainTemplate`, `headerPartial`, `commitPartial`, and `footerPartial` options are also fully overridable from caller input.

### [medium] Unescaped template rendering

Finding ID: `NPS-3E71DDD739AC`

File: `dist/template.js:76`

Handlebars templates are compiled with `noEscape: true`, disabling HTML escaping. If any commit messages or context data are user-controlled, this could lead to template injection or XSS when the generated changelog is rendered in a browser.

### [low] Source map inclusion

Finding ID: `NPS-B51B3A6899B5`

File: `dist/cli/index.js:66`

The file includes an inline base64 source map (//# sourceMappingURL=data:application/json;base64,...). While common in build artifacts, source maps can expose original source paths and internal logic; they are not inherently malicious but are noted for completeness.

### [low] Source map inclusion

Finding ID: `NPS-B94C3C105085`

File: `dist/cli/utils.js:59`

The file contains an inline base64-encoded source map comment. Source maps can expose original source code and internal file paths, which may aid attackers in understanding the application structure. While not inherently malicious, it is a security hygiene issue.

## Files reviewed

- `dist/cli/index.js` (medium): The CLI entrypoint appears to be a legitimate changelog writer, but it loads user-specified JavaScript files for context and options, which is a potential arbitrary code execution vector that depends on the unimplemented loadDataFile helper.
- `dist/cli/utils.js` (medium): The code exhibits a dynamic import vulnerability due to external input, but no clear malicious patterns were found.
- `dist/template.js` (medium): No malicious patterns found; however, the use of Handlebars with noEscape and externally supplied templates/partials introduces template injection and XSS risks if inputs are untrusted.
- `dist/commit.js` (safe): No malicious patterns detected; the code only provides a read-only proxy wrapper for commit objects and applies transformation functions.
- `dist/context.js` (safe): No malicious patterns detected in the context.js file; it contains only pure functions for grouping commits/notes and preparing template context.
- `dist/index.js` (safe): No malicious patterns detected; the file contains only standard module exports and a source map comment.
- `dist/options.js` (safe): No malicious patterns detected in the provided options.js file; it contains only benign configuration and data transformation logic.
- `dist/types/commit.js` (safe): No malicious patterns detected; the file only contains an empty export and a benign base64 source map reference.
- `dist/types/context.js` (safe): No malicious patterns detected
- `dist/types/index.js` (safe): The file only re-exports type definitions and contains an inline source map; no malicious patterns were detected.
- `dist/types/options.js` (safe): The file contains only an empty export statement and an inline source map with no executable code, making it benign.
- `dist/types/utils.js` (safe): The file is an empty ES module with only a source map comment; no executable or malicious code is present.
- `dist/utils.js` (safe): No malicious patterns detected; the file contains only benign utility functions for date formatting, safe JSON stringification, and comparator creation.
- `dist/writers.js` (safe): No malicious patterns detected; the code is a legitimate changelog generation module using standard stream transforms and no risky operations.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
