# cosmiconfig@9.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:53.000Z
- Files reviewed: 14
- Findings: 2 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/cosmiconfig
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package cosmiconfig@9.0.0 on Oct 6, 2026. An AI review of 14 source files produced 2 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic Code Execution

Finding ID: `NPS-8D184837CF3B`

File: `dist/loaders.js`

The module dynamically requires and executes code from external files using 'import-fresh', 'typescript', 'js-yaml', and 'parse-json'. While these are legitimate loaders for configuration files, the dynamic import and require mechanisms could be exploited if an attacker can control the input file paths or content, leading to arbitrary code execution. Additionally, the loader writes transpiled TypeScript to the filesystem and then imports it, which could be abused to execute malicious code if the input TypeScript is attacker-controlled.

### [medium] File System Manipulation

Finding ID: `NPS-387C308DF552`

File: `dist/loaders.js`

The loadTsSync and loadTs functions write compiled TypeScript files to the filesystem (compiledFilepath) and subsequently remove them. This could be abused to write files outside the intended directory if the filepath is user-controlled, potentially leading to unauthorized file writes or deletion. However, the file extensions are fixed (.cjs and .mjs) and the paths are derived from the input filepath.

### [low] Cache manipulation

Finding ID: `NPS-A788F33165CE`

File: `dist/Explorer.js:28`

The code uses caching mechanisms (loadCache, searchCache) to store loaded configuration results. While not inherently malicious, caching could lead to stale or unintended data being served if the cache is not properly scoped or cleared.

### [low] File system traversal

Finding ID: `NPS-D2C740B792EC`

File: `dist/Explorer.js:36`

The search method traverses the filesystem upwards from a starting directory, checking for configuration files in parent directories and global locations. This is standard behavior for configuration loaders (like cosmiconfig) but could be used to discover sensitive files outside the intended package scope.

### [low] Dynamic file loading

Finding ID: `NPS-2C23529332DD`

File: `dist/Explorer.js:100`

The code supports $import directives in configuration files, allowing one config to load and merge other configuration files from the filesystem. While intended for legitimate config merging, this could be abused to read arbitrary files if an attacker can control config file contents, potentially leading to information disclosure if the loaded config data is later exposed or exfiltrated.

### [low] dynamic code execution

Finding ID: `NPS-9F9EBB3E5493`

File: `dist/canUseDynamicImport.js:10`

The function uses `new Function('id', 'return import(id);')` solely to test whether the runtime supports dynamic import syntax. No user input is passed, no code is executed from external sources, and the constructed function is never invoked. This is a benign feature-detection pattern commonly used by Babel and similar tools.

## Files reviewed

- `dist/Explorer.js` (medium): The code appears to be a legitimate configuration file explorer with no obvious malicious patterns, but it includes dynamic file loading and filesystem traversal features that could be misused in certain scenarios.
- `dist/loaders.js` (medium): The code is a legitimate set of loaders for configuration and TypeScript files, but it uses dynamic imports and filesystem writes that could pose a risk if input paths are untrusted; no direct malicious patterns were found.
- `dist/ExplorerBase.js` (safe): No malicious patterns detected; this is a legitimate cosmiconfig-style configuration file explorer utility.
- `dist/ExplorerSync.js` (safe): No malicious patterns detected; the code implements a configuration file explorer with file reading and import merging, but lacks any exfiltration, obfuscation, or process execution behavior.
- `dist/cacheWrapper.js` (safe): No malicious patterns detected; the code is a simple cache wrapper utility with no network, filesystem, or process access.
- `dist/canUseDynamicImport.js` (safe): The code is a benign feature-detection helper that uses `new Function` only to check for dynamic import support without executing external code or exhibiting any malicious behavior.
- `dist/defaults.js` (safe): No malicious patterns detected; the file only defines configuration search paths and default loader mappings using standard loaders.
- `dist/getDirectory.js` (safe): No malicious patterns detected; the code only uses path utilities and path-type to resolve directory paths without any network, filesystem, process, or dynamic execution activity.
- `dist/getPropertyByPath.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected; the file is a standard cosmiconfig library entry point that only uses relative requires and in-process configuration search logic.
- `dist/merge.js` (safe): No malicious patterns detected; the code is a straightforward deep merge utility with no network, filesystem, process execution, or obfuscated behavior.
- `dist/readFile.js` (safe): No malicious patterns detected; the file only provides standard file reading utilities using Node's fs module.
- `dist/types.js` (safe): No malicious patterns detected
- `dist/util.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
