# dotenv@18.0.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T15:39:48.000Z
- Files reviewed: 2
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/dotenv
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package dotenv@18.0.5 on Oct 4, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Process spawning and shell command execution

Finding ID: `NPS-2313E0456C33`

File: `dist/index.cjs`

The bundled 'dotenv run' CLI utility spawns child processes via child_process. On Windows, it falls back to spawning cmd.exe with a constructed command string using windowsVerbatimArguments. This is legitimate functionality for a CLI runner but represents a process-execution surface.

### [low] Environment variable harvesting

Finding ID: `NPS-01F0A865FBAD`

File: `dist/index.cjs`

The code reads, parses, and injects environment variables from .env files into process.env. This is the documented behavior of the dotenv package but does touch environment variables broadly.

### [low] Credentials file access potential via user-specified paths

Finding ID: `NPS-6E546CEDFD94`

File: `dist/index.cjs`

The CLI supports -f/--file options that accept arbitrary paths to read .env-style files. If invoked with hostile arguments this could be used to read arbitrary files that parse as dotenv format, but this is intended, user-controlled CLI behavior.

## Files reviewed

- `dist/index.cjs` (medium): This is the legitimate dotenv package with its 'dotenv run' CLI; no malicious exfiltration, backdoors, or obfuscated payloads were found, though it does spawn child processes and manipulate environment variables as intended functionality.
- `dist/config.cjs` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of dotenv are flagged high or critical. The latest scanned version, 18.0.5, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 18.0.5 (`18.0.5`): medium
- 17.2.3 (`17.2.3`): clean
- 16.4.5 – 16.6.1 (`>=16.4.5 <=16.6.1`): not scanned

## Scanned versions

- [18.0.5](https://security.togoder.click/npm/dotenv@18.0.5): medium, 2026-10-04T15:39:48.000Z
- [17.2.3](https://security.togoder.click/npm/dotenv@17.2.3): safe, 2026-05-15T12:29:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
