# js-yaml@4.3.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:17:11.000Z
- Files reviewed: 27
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/js-yaml
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package js-yaml@4.3.2 on Oct 6, 2026. An AI review of 27 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Prototype pollution protection

Finding ID: `NPS-80FC0B0E88AC`

File: `lib/loader.js`

The setProperty function uses Object.defineProperty for the __proto__ key to protect against prototype pollution, consistent with the referenced GitHub issue.

### [low] Resource exhaustion protection

Finding ID: `NPS-0B5A029D46DE`

File: `lib/loader.js`

maxDepth and maxTotalMergeKeys limits mitigate denial-of-service via deeply nested structures or excessive merge keys.

## Files reviewed

- `bin/js-yaml.js` (safe): No malicious patterns detected
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/common.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dumper.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/exception.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index_vite_proxy.tmp.mjs` (safe): No malicious patterns detected
- `lib/loader.js` (safe): This is the standard js-yaml loader with explicit prototype-pollution and resource-limit safeguards; no malicious patterns detected.
- `lib/schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/schema/core.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/schema/default.js` (safe): No malicious patterns detected; the file only extends a YAML schema with standard type definitions.
- `lib/schema/failsafe.js` (safe): No malicious patterns detected; this is a standard YAML Failsafe schema definition with only static local requires.
- `lib/schema/json.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/snippet.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/binary.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/bool.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/float.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/int.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/map.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/merge.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/null.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/omap.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/pairs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/seq.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/set.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/str.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/type/timestamp.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of js-yaml are flagged high or critical. The latest scanned version, 4.3.2, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.3.2 (`4.3.2`): clean
- 4.1.1 – 4.3.0 (`>=4.1.1 <=4.3.0`): not scanned
- 4.1.0 (`4.1.0`): clean
- 3.15.0 – 3.15.2 (`>=3.15.0 <=3.15.2`): not scanned

## Scanned versions

- [4.3.2](https://security.togoder.click/npm/js-yaml@4.3.2): safe, 2026-10-06T14:17:11.000Z
- [4.1.0](https://security.togoder.click/npm/js-yaml@4.1.0): safe, 2026-05-15T12:32:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
