# jayson@4.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:33:37.000Z
- Files reviewed: 32
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/jayson
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package jayson@4.2.0 on Oct 4, 2026. An AI review of 32 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Unsanitized parameter parsing

Finding ID: `NPS-93BB5E8D9C5F`

File: `bin/jayson.js:15`

Parameters passed via --params are parsed with JSON.parse and forwarded to the remote endpoint. Not an internal vulnerability, but part of the expected network request behavior.

### [low] Network request capability

Finding ID: `NPS-DA98C9D7048E`

File: `bin/jayson.js:37`

The CLI acts as a JSON-RPC client that can connect to arbitrary HTTP, HTTPS, or TCP endpoints specified via --url or --socket. While expected for this tool, it could be abused to send requests to attacker-controlled servers if invoked maliciously.

### [low] Dynamic socket address parsing

Finding ID: `NPS-94CCAF762424`

File: `bin/jayson.js:66`

parseSocket tokenizes user input with ':' and can construct TCP socket connections to arbitrary IP/host addresses. No external data is harvested, but unrestricted outbound connection targets are supported.

## Files reviewed

- `bin/jayson.js` (medium): The script is a legitimate JSON-RPC client CLI with no signs of data exfiltration, credential harvesting, obfuscation, backdoors, or install-time execution; only expected outbound network request capabilities are present.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/client/browser/index.js` (safe): No malicious patterns detected
- `lib/client/http.js` (safe): No malicious patterns detected
- `lib/client/https.js` (safe): No malicious patterns detected
- `lib/client/index.js` (safe): No malicious patterns detected in the analyzed client module.
- `lib/client/tcp.js` (safe): No malicious patterns detected; the file implements a standard Jayson TCP client using net.connect and no suspicious data exfiltration, credential harvesting, or dynamic code execution.
- `lib/client/tls.js` (safe): No malicious patterns detected
- `lib/client/websocket.js` (safe): No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client implementation for the Jayson library.
- `lib/generateRequest.js` (safe): No malicious patterns detected; the code is a standard JSON-RPC request generator with no network, filesystem, or process activity.
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/method.js` (safe): No malicious patterns detected in the Method constructor and execution logic; it is a benign RPC method wrapper with no network, filesystem, process, or dynamic code execution activity.
- `lib/server/http.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/server/https.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/server/index.js` (safe): No malicious patterns detected in the server implementation; it is a standard JSON-RPC server module with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/server/middleware.js` (safe): No malicious patterns detected; the middleware is a standard JSON-RPC over HTTP handler with no data exfiltration, obfuscation, process spawning, or filesystem access.
- `lib/server/tcp.js` (safe): No malicious patterns detected; the code is a standard Jayson TCP server implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `lib/server/tls.js` (safe): No malicious patterns detected
- `lib/server/websocket.js` (safe): No malicious patterns detected; the code implements a standard JSON-RPC WebSocket server without any suspicious behavior.
- `lib/utils.js` (safe): The code is a JSON-RPC utility module that parses streams, handles HTTP requests, and serializes JSON without any suspicious network, filesystem, process, credential-harvesting, or dynamic-code-execution patterns.
- `promise/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `promise/lib/client/browser/index.js` (safe): No malicious patterns detected; the code is a standard Promise wrapper for a Jayson browser client with no external data transmission, credential harvesting, obfuscation, or install-time execution.
- `promise/lib/client/http.js` (safe): No malicious patterns detected in the promise client HTTP wrapper.
- `promise/lib/client/https.js` (safe): No malicious patterns detected; the file is a simple promisified wrapper around Jayson's HTTPS client and contains no exfiltration, obfuscation, process spawning, or suspicious filesystem/network activity.
- `promise/lib/client/index.js` (safe): No malicious patterns detected; the code is a standard promise wrapper for a JSON-RPC client library.
- `promise/lib/client/tcp.js` (safe): No malicious patterns detected; the file is a straightforward promise wrapper for a Jayson TCP client with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `promise/lib/client/tls.js` (safe): No malicious patterns detected; the file is a standard promisified TLS client wrapper for the Jayson library.
- `promise/lib/client/websocket.js` (safe): No malicious patterns detected
- `promise/lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `promise/lib/method.js` (safe): No malicious patterns detected
- `promise/lib/server.js` (safe): Cleared by Jev triage; no further analysis needed
- `promise/lib/utils.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
