# fast-redact@3.5.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:31:24.000Z
- Files reviewed: 17
- Findings: 1 high, 3 medium severity findings
- Report: https://security.togoder.click/npm/fast-redact
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fast-redact@3.5.0 on Oct 4, 2026. An AI review of 17 source files produced 1 high, 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Potential injection through template construction

Finding ID: `NPS-8630948E61F5`

File: `lib/redactor.js:28`

The `redactTmpl` function interpolates `path`, `escPath`, `arrPath`, and other path-derived strings directly into the generated code. If an attacker can control the keys of the `secret` object (e.g., through a prototype pollution or crafted configuration), they could inject malicious JavaScript into the generated function. The code uses `JSON.stringify` for some values (e.g., `arrPath`, `p` in circular detection) but not all; `path` and `escPath` are used raw inside template literals that become code. This could lead to code injection if the secret paths are not properly sanitized.

### [medium] Dynamic code execution via new Function

Finding ID: `NPS-99837E6ED55A`

File: `lib/redactor.js:6`

The redactor function uses `Function('o', ...)` to construct a redaction function from a string template. While the input string is built internally from the secret paths and configuration, this pattern is a form of dynamic code generation. If the input to `redactor` (specifically the `secret` object keys/paths) can be influenced by untrusted data, it could lead to arbitrary code execution. However, the paths are typically derived from configuration, not direct user input. Nonetheless, the use of `new Function` is a significant code smell.

### [medium] Dynamic code execution

Finding ID: `NPS-B9B0D2DA392E`

File: `lib/restorer.js:18`

The code uses the Function constructor to dynamically create a restore function from a template string. While the inputs are derived from the 'secret' object and paths controlled by the caller, this pattern can be risky if the inputs are not properly sanitized, potentially leading to code injection. However, in this context, it appears to be a deliberate design choice for performance reasons, with internal state binding.

### [medium] Dynamic code execution

Finding ID: `NPS-C554D946A20A`

File: `lib/validator.js:23`

The code uses the Function constructor to dynamically execute a string containing user-provided paths. Although the input is validated against a limited set of characters and patterns, this is a risky pattern that could potentially lead to code injection if the validation is bypassed.

## Files reviewed

- `lib/redactor.js` (medium): The code uses `new Function` to generate redaction logic dynamically, and interpolates secret paths into the generated code without full sanitization, posing a risk of code injection if secret paths are attacker-controlled.
- `lib/restorer.js` (medium): The code uses dynamic function generation via the Function constructor, which is a potential security concern if inputs are not strictly controlled, but no immediate malicious patterns like exfiltration or backdoors were found.
- `lib/validator.js` (medium): The validator uses dynamic code execution via Function constructor for path validation, which is a risky pattern but appears to have some input sanitization.
- `benchmark/index.js` (safe): No malicious patterns detected
- `example/default-usage.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/intermediate-wildcard-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/multi-wildcard-array-depth.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/multi-wildcard-array-end.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/multi-wildcard-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/serialize-false.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/serialize-function.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/top-wildcard-object.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected
- `lib/modifiers.js` (safe): No malicious patterns detected; the code appears to be a legitimate redaction/restoration utility for pino logging.
- `lib/parse.js` (safe): No malicious patterns detected; the file only parses path strings into a structured format using local regex logic.
- `lib/rx.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/state.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
