# fast-stable-stringify@1.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:31:35.000Z
- Files reviewed: 13
- Findings: 2 high, 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/fast-stable-stringify
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fast-stable-stringify@1.0.0 on Oct 4, 2026. An AI review of 13 source files produced 2 high, 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Command injection via shell execSync

Finding ID: `NPS-D226154C91AB`

File: `util/get-git-hash-sync.js:13`

The function passes its filePath parameter directly into two shell command strings executed via child_process.execSync without sanitization or escaping. If filePath is attacker-controlled or derived from external input, this allows arbitrary command execution through shell metacharacters (e.g., '; rm -rf /', '$(...)', '&& ...').

### [high] Unescaped shell command construction

Finding ID: `NPS-9718DF7A6B91`

File: `util/get-git-hash-sync.js:17`

Second execSync call similarly concatenates filePath into the git log command string, providing another command injection vector with the same untrusted-input risk.

### [medium] Dynamic module loading

Finding ID: `NPS-54C2F6008D8B`

File: `util/get-lib-info.js:13`

The code uses require(libName + '/package.json') where libName is a user-supplied parameter. If libName is not strictly validated before being passed to this function, an attacker could potentially load arbitrary package.json files from other installed packages or manipulate the module path resolution. This could lead to information disclosure of package metadata or unexpected code paths, though the impact is limited to reading package.json files.

### [low] Swallowed exception masks state

Finding ID: `NPS-1C2C07540C9B`

File: `util/get-git-hash-sync.js:12`

The try/catch around the diff-index check silently ignores errors (the intended throw is commented out), meaning callers relying on the documented 'throws on uncommitted changes' contract may receive a hash for a dirty working tree. This is a correctness/robustness issue that can hide failures.

### [low] Potential path traversal in module resolution

Finding ID: `NPS-7A2BAF39CB27`

File: `util/get-lib-info.js:13`

The dynamic require with computed input could allow path traversal if libName contains sequences like '../' to escape the intended package scope and load package.json from arbitrary locations accessible via Node's module resolution. This may expose internal package structure or configuration details but does not directly execute arbitrary code from the target file.

## Files reviewed

- `util/get-git-hash-sync.js` (medium): The utility executes git commands via execSync with unsanitized filePath interpolation, creating a command-injection risk if the argument is not fully trusted, though no data exfiltration, backdoor, or install-time execution was observed.
- `util/get-lib-info.js` (medium): The code uses dynamic module loading with user-influenced input, creating a potential risk of unintended package.json disclosure, but no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found.
- `cli/files-to-comparison-results.js` (safe): Cleared by Jev triage; no further analysis needed
- `cli/format-table.js` (safe): Cleared by Jev triage; no further analysis needed
- `cli/index.js` (safe): This CLI utility uses standard Node.js modules for argument parsing, file globbing, and table formatting without any malicious patterns such as credential harvesting, obfuscation, network exfiltration, or process execution.
- `fixtures/index.js` (safe): No malicious patterns detected; the file only exports a static require of a local module.
- `fixtures/input-data-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `karma.conf.js` (safe): No malicious patterns detected in the Karma configuration file; it is a standard test runner setup with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `karma.conf.travis.js` (safe): No malicious patterns detected
- `util/eachRecursive.js` (safe): No malicious patterns detected
- `util/object-path.js` (safe): Cleared by Jev triage; no further analysis needed
- `v8-profile/bench.js` (safe): No malicious patterns detected; the file is a straightforward benchmark that imports local modules and runs stringification in a loop.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
