# convert-source-map@2.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:51.000Z
- Files reviewed: 1
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/convert-source-map
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package convert-source-map@2.0.0 on Oct 6, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] File system read via user-supplied callback

Finding ID: `NPS-2D15D52AFC96`

File: `index.js:60`

The `readFromFileMap` function accepts a `read` parameter that is called with a filename extracted from a sourceMappingURL comment. This allows arbitrary file reads if the caller passes a permissive read function (e.g., `fs.readFileSync`). While this is an intended API feature for reading source map files, it could be abused if untrusted input reaches this function, potentially enabling reading of sensitive files like `/etc/passwd` or credentials. The package itself does not confine the path to the current working directory.

### [low] Dynamic code execution via Buffer and JSON.parse

Finding ID: `NPS-8FE4D740B466`

File: `index.js:115`

The code uses `JSON.parse` on decoded base64/URI content and Buffer constructors. While JSON.parse is not code execution, it can be exploited for prototype pollution if the input is attacker-controlled. No direct eval or new Function is present, but the package processes untrusted sourcemap comments and constructs objects from them, which could lead to prototype pollution in consumers.

### [low] Potential data exfiltration through sourcemap comments

Finding ID: `NPS-ED913F4CC3C9`

File: `index.js:200`

The functions `fromComment`, `fromSource`, and `fromMapFileSource` parse sourceMappingURL comments that may contain base64 or URI-encoded data. Although this module does not send data externally, it decodes and embeds arbitrary data from comments into sourcemap objects. If a malicious sourcemap is later used by a tool that uploads sourcemaps to a remote service, it could lead to unintended data exposure. This is a design risk rather than direct malware.

## Files reviewed

- `index.js` (medium): The code is a legitimate sourcemap conversion utility, but it exposes an API that can read arbitrary files via a user-supplied callback and processes untrusted sourcemap comments, posing medium-risk for path traversal and potential data exposure if misused.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
