# libnpmversion@8.0.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:24.000Z
- Files reviewed: 8
- Findings: 4 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/libnpmversion
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package libnpmversion@8.0.4 on Oct 6, 2026. An AI review of 8 source files produced 4 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential argument injection

Finding ID: `NPS-F3993C267442`

File: `lib/tag.js:9`

The `tag` value is built by concatenating `tagVersionPrefix` and `version` without validation. If `version` or `tagVersionPrefix` begins with `-`, it could be interpreted as a git option rather than a tag name, potentially allowing argument injection into the spawned git command.

### [medium] Process spawning / shell command execution

Finding ID: `NPS-C82272DCE784`

File: `lib/tag.js:22`

The module invokes git.spawn(...) from @npmcli/git, which spawns a child process to run the git tag command. Although the arguments are passed as an array (not a shell string), this is still external process execution and is a potential attack surface if inputs like tag, message, or opts are influenced by untrusted sources.

### [medium] Arbitrary script execution

Finding ID: `NPS-A85A2E3366EE`

File: `lib/version.js`

The module calls runScript (from @npmcli/run-script) to execute package lifecycle scripts ('preversion', 'version', 'postversion'). This is by design for npm versioning, but it means arbitrary code from package.json scripts will be executed. If a malicious package.json is processed, this could lead to code execution.

### [medium] File system manipulation

Finding ID: `NPS-494AF256E0E7`

File: `lib/version.js`

The module writes to package.json, package-lock.json, and npm-shrinkwrap.json on disk. Modifying package.json via writeJson could be abused if 'pkg' object is influenced by untrusted input, potentially injecting malicious scripts or dependencies into the package.json.

### [low] User-controlled message interpolation

Finding ID: `NPS-061B20D1891B`

File: `lib/tag.js:25`

`message.replace(/%s/g, version)` interpolates the supplied version into a git tag message. Combined with `-m` in the flags, an attacker-controlled message could potentially alter git behavior or inject unexpected content, depending on how @npmcli/git constructs and escapes arguments.

### [low] Spawning processes / shell commands

Finding ID: `NPS-FD3DC641AB1F`

File: `lib/version.js`

The module uses git.spawn (from @npmcli/git) to execute git commands such as 'git add', 'git commit', and 'git tag'. While these are expected operations for a versioning tool, spawning external processes introduces risk if arguments are user-controlled or if the git binary is hijacked.

## Files reviewed

- `lib/tag.js` (medium): The file is likely part of a legitimate npm versioning workflow, but it spawns git processes with user-influenced arguments and lacks validation, creating argument-injection and command-execution risk if inputs are untrusted.
- `lib/version.js` (medium): The code performs expected npm versioning operations but uses script execution and process spawning that could be risky if inputs are untrusted.
- `lib/commit.js` (safe): No malicious patterns detected
- `lib/enforce-clean.js` (safe): No malicious patterns detected
- `lib/index.js` (safe): No malicious patterns detected
- `lib/read-json.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/retrieve-tag.js` (safe): The code uses @npmcli/git to run git describe and semver to parse the tag; no malicious patterns or security concerns were detected.
- `lib/write-json.js` (safe): No malicious patterns detected; the code only serializes a package.json object and writes it back to disk using standard Node.js APIs.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
