# lit-html@3.3.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:34:21.000Z
- Files reviewed: 120
- Findings: 11 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/lit-html
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package lit-html@3.3.1 on Oct 4, 2026. An AI review of 120 source files produced 11 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Intentional unsafe HTML rendering

Finding ID: `NPS-0A113B18E542`

File: `development/directives/unsafe-html.js:38`

The unsafeHTML directive explicitly bypasses HTML escaping and renders raw HTML into the DOM. While this is a documented and intentional feature of the lit-html library, it is a dangerous pattern that can lead to cross-site scripting (XSS) if any user-controlled data is passed to it. The code even includes a warning comment about this danger.

### [medium] TemplateResult impersonation

Finding ID: `NPS-AA6D7F1130AE`

File: `development/directives/unsafe-html.js:39`

The directive manually constructs an object that mimics a lit-html TemplateResult, including internal properties like '_$litType$'. The code comments acknowledge this is 'extremely dangerous' and that third-party directives should not do this. This could allow bypassing framework safety mechanisms if the directive is misused or compromised.

### [medium] Unsafe HTML/SVG rendering by design

Finding ID: `NPS-78781B2114E9`

File: `development/directives/unsafe-svg.js:1`

This directive intentionally bypasses sanitization and renders raw SVG content, which can enable XSS if used with untrusted input. The file's own documentation warns about this. It is an expected part of lit-html's API, not a malicious payload, but it is a security-sensitive feature.

### [medium] unsafe HTML injection

Finding ID: `NPS-0AFA10252A98`

File: `development/static.js`

The `unsafeStatic` function allows arbitrary strings to be treated as static template content, bypassing Lit's normal HTML sanitization. The code explicitly warns that this function is unsafe for untrusted content and can lead to XSS if user input is passed to it. This is a deliberate API, but it represents a security-sensitive sink within the package.

### [medium] unsafe template cache key construction

Finding ID: `NPS-201009569167`

File: `development/static.js`

The `withStatic` function builds a cache key by joining static strings with '$$lit$$' and stores the resulting `staticStrings` array without escaping. The comment itself notes that 'in general this pattern is unsafe' and may bypass Lit's security checks. This can create template instances with attacker-influenced static strings if `unsafeStatic` is used with untrusted input.

### [medium] Intentional unsafe HTML rendering directive

Finding ID: `NPS-62EF1ADB747D`

File: `directives/unsafe-html.js:12`

This file defines the `unsafeHTML` directive from the Lit library. Despite being an official Google/Lit component, its entire purpose is to inject raw, unescaped HTML into the DOM (`resultType=1` corresponds to HTML part rendering, bypassing Lit's default escaping). If the string passed to this directive ever originates from untrusted input, it enables XSS. The name itself documents the risk, and no sanitization is performed here. This is a security-relevant capability rather than a supply-chain compromise, but it is the kind of primitive a malicious package could abuse.

### [medium] Potential Cross-Site Scripting (XSS) Risk

Finding ID: `NPS-EE02602557C2`

File: `node/development/directives/template-content.js:28`

The templateContent directive renders the content of a template element as HTML using document.importNode. The code comments explicitly warn that the template should be developer-controlled and not user-controlled, as rendering a user-controlled template could lead to cross-site-scripting vulnerabilities. This is not a malicious pattern but a security risk if misused.

### [medium] Direct rendering bypass of framework safety

Finding ID: `NPS-7EDF0D8C5432`

File: `node/development/directives/unsafe-html.js:31`

The render() method does not perform any sanitization (no DOMPurify, no escaping) and only enforces a type check that the value is a string. Any sanitization responsibility is delegated entirely to the caller, and there is no safe default. Because it constructs a fake TemplateResult with 'raw' strings, it forces Lit to insert the content via innerHTML-like parsing rather than text nodes.

### [medium] Intentional XSS Risk (unsafe HTML rendering)

Finding ID: `NPS-6881F74A1E1F`

File: `node/development/directives/unsafe-html.js:45`

The directive 'unsafeHTML' renders a string as raw HTML by impersonating a Lit TemplateResult ('_$litType$' set to HTML_RESULT with the raw string as the template). This bypasses Lit's built-in escaping and will execute any embedded scripts/event handlers, leading to DOM-based cross-site scripting if used with untrusted input. The source even includes comments warning it is 'extremely dangerous' and 'unsafe to use with any user-provided input that hasn't been sanitized or escaped'. This is documented/by-design behavior of the library, not a hidden backdoor, but it is a significant security hazard for consumers of the package.

### [medium] Unsafe rendering by design

Finding ID: `NPS-EC9231890C4F`

File: `node/development/directives/unsafe-svg.js:26`

This directive intentionally renders unsanitized SVG content via innerHTML-like behavior (inherited from UnsafeHTMLDirective). Its name and JSDoc explicitly warn that using it with user-provided input can lead to XSS. This is a known, documented API surface in Lit, not a hidden backdoor, but it is a dangerous primitive if consumers pass untrusted data to it.

### [medium] Intentional unsafe HTML rendering directive

Finding ID: `NPS-62EF1ADB747D`

File: `node/directives/unsafe-html.js:12`

This file defines the `unsafeHTML` directive from the Lit library. Despite being an official Google/Lit component, its entire purpose is to inject raw, unescaped HTML into the DOM (`resultType=1` corresponds to HTML part rendering, bypassing Lit's default escaping). If the string passed to this directive ever originates from untrusted input, it enables XSS. The name itself documents the risk, and no sanitization is performed here. This is a security-relevant capability rather than a supply-chain compromise, but it is the kind of primitive a malicious package could abuse.

### [low] global symbol brand spoofing

Finding ID: `NPS-ADD60B39BA1F`

File: `development/static.js`

`Symbol.for('')` creates a globally shared symbol. Any other code in the same JavaScript realm can obtain the same symbol and forge objects that pass the `unwrapStaticValue` check, potentially injecting arbitrary static content into templates if such forged objects reach `withStatic`. The package documentation acknowledges interoperability goals but not this spoofing risk.

### [low] Minified/obfuscated source

Finding ID: `NPS-4B182EC6B3EC`

File: `directives/unsafe-html.js:1`

The code is heavily minified with short identifiers (e.g. `t`, `i`, `r`, `s`, `e`, `o`). While this is normal for published build artifacts and no obfuscation beyond minification is present, it reduces auditability and could conceal modifications relative to upstream source. The accompanying sourcemap reference suggests it is a legitimate build output.

### [low] intentional unsafe API

Finding ID: `NPS-78ABAA566A06`

File: `node/development/static.js:47`

The 'unsafeStatic' function and related static value handling deliberately bypass lit-html's normal sanitization, allowing direct HTML injection. This is a documented, intentional API for trusted content only, not a malicious pattern. The code and comments explicitly warn users not to pass untrusted input.

### [low] template cache key manipulation

Finding ID: `NPS-E129FA990F23`

File: `node/development/static.js:118`

The withStatic wrapper sets 'staticStrings.raw = staticStrings' and caches templates by a joined key. This is noted in comments as bypassing lit's security checks for static values. It is an intentional implementation detail required for the static value feature and not a covert backdoor.

### [low] Minified/obfuscated source

Finding ID: `NPS-4B182EC6B3EC`

File: `node/directives/unsafe-html.js:1`

The code is heavily minified with short identifiers (e.g. `t`, `i`, `r`, `s`, `e`, `o`). While this is normal for published build artifacts and no obfuscation beyond minification is present, it reduces auditability and could conceal modifications relative to upstream source. The accompanying sourcemap reference suggests it is a legitimate build output.

### [low] dynamic HTML parsing

Finding ID: `NPS-E24475933D5E`

File: `node/lit-html.js`

The N.createElement method assigns a string to a template element's innerHTML. In this library the string is derived from validated template literal arrays passed through the P() function (which creates a Trusted Type when available), not from unsanitized user input. This is intrinsic to lit-html's templating design and is not exfiltration or code execution.

### [low] trusted types policy

Finding ID: `NPS-4E59DE117244`

File: `node/lit-html.js:5`

The code creates a Trusted Types policy named 'lit-html' via globalThis.trustedTypes. This is a standard security feature used by lit-html to integrate with the browser's Trusted Types enforcement, not a malicious pattern.

### [low] randomized marker generation

Finding ID: `NPS-6559476A0168`

File: `node/lit-html.js:5`

Math.random() is used to generate a unique marker string for template processing. This is a benign uniqueness mechanism, not cryptographic or security-sensitive, and does not indicate malicious intent.

## Files reviewed

- `development/directives/unsafe-html.js` (medium): The code is a legitimate part of the lit-html library implementing the documented unsafeHTML directive, which intentionally allows raw HTML rendering; the security concerns are inherent to its purpose and mitigated by clear warnings, but it remains a potential XSS vector if misused.
- `development/directives/unsafe-svg.js` (medium): No malicious patterns detected; this is a legitimate lit-html directive for rendering unsanitized SVG with documented XSS risks.
- `development/static.js` (medium): No malicious exfiltration, credential harvesting, or backdoor behavior found; the main concerns are documented but security-sensitive unsafe HTML injection and template-cache manipulation capabilities inherent to the library's API.
- `directives/unsafe-html.js` (medium): This is the legitimate Lit `unsafeHTML` directive; it performs no network, filesystem, process, or credential access, but by design injects unescaped HTML and therefore carries inherent XSS risk if fed untrusted input.
- `node/development/directives/template-content.js` (medium): No malicious patterns detected, but the directive can introduce XSS if used with untrusted templates.
- `node/development/directives/unsafe-html.js` (medium): The file is an intentional, documented 'unsafeHTML' directive from Lit that allows raw HTML injection (XSS) by design; no exfiltration, credential harvesting, obfuscation, process spawning, or network activity was found, but it should be flagged as a dangerous API for consumers handling untrusted data.
- `node/development/directives/unsafe-svg.js` (medium): The file defines Lit's documented unsafeSVG directive which deliberately renders unsanitized SVG (an XSS risk if misused), but contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution.
- `node/directives/unsafe-html.js` (medium): This is the legitimate Lit `unsafeHTML` directive; it performs no network, filesystem, process, or credential access, but by design injects unescaped HTML and therefore carries inherent XSS risk if fed untrusted input.
- `async-directive.js` (safe): No malicious patterns detected; this is a legitimate Google Lit library file implementing an async directive with no external network, filesystem, or process activity.
- `development/async-directive.js` (safe): No malicious patterns detected
- `development/directive-helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directive.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/async-append.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/async-replace.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/cache.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/choose.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/class-map.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/guard.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/if-defined.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/join.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/keyed.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/live.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/map.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/private-async-helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/range.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/ref.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/repeat.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/style-map.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/template-content.js` (safe): No malicious patterns detected; this is a legitimate Lit directive for rendering developer-controlled template content with an explicit XSS warning.
- `development/directives/unsafe-mathml.js` (safe): No malicious patterns detected; the file is a standard Lit unsafeMathML directive with no network, filesystem, process, or code-execution behavior.
- `development/directives/until.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/directives/when.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/is-server.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/lit-html.js` (safe): This is the legitimate Google Lit library's development build, with no malicious patterns detected.
- `development/polyfill-support.js` (safe): No malicious patterns detected; the code is a legitimate Lit polyfill for ShadyDOM/ShadyCSS compatibility with no exfiltration, obfuscation, or unsafe operations.
- `development/private-ssr-support.js` (safe): No malicious patterns detected; the file is a legitimate Lit library private SSR support module with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `directive-helpers.js` (safe): This is a minified but non-obfuscated excerpt from the Lit library (Google LLC, BSD-3-Clause) containing only template rendering helpers with no malicious patterns.
- `directive.js` (safe): No malicious patterns detected
- `directives/async-append.js` (safe): This is a legitimate Lit async-append directive, containing no malicious patterns, network activity, filesystem access, or obfuscated code.
- `directives/async-replace.js` (safe): This is the legitimate Lit AsyncReplace directive from Google's lit-html library with no malicious patterns detected.
- `directives/cache.js` (safe): This is the official lit-html cache directive from Google's Lit library; no malicious patterns, exfiltration, obfuscation, or dangerous operations detected.
- `directives/choose.js` (safe): No malicious patterns detected; the code is a simple utility function with no security concerns
- `directives/class-map.js` (safe): No malicious patterns detected; this is the standard Lit classMap directive from Google's lit-html library.
- `directives/guard.js` (safe): This is the standard `guard` directive from the Lit library (Google), containing no malicious patterns, no network/filesystem access, and no dynamic code execution.
- `directives/if-defined.js` (safe): The file is a small, legitimate Lit library directive that maps undefined/null values to a 'nothing' sentinel, with no malicious patterns detected.
- `directives/join.js` (safe): No malicious patterns detected
- `directives/keyed.js` (safe): No malicious patterns detected; the file is a legitimate Lit directive for keyed rendering.
- `directives/live.js` (safe): No malicious patterns detected; this is the standard Lit 'live' directive implementation with only internal imports and no external data access or code execution.
- `directives/map.js` (safe): No malicious patterns detected
- `directives/private-async-helpers.js` (safe): No malicious patterns detected; the code is a legitimate Google Lit helper module for async iteration and weak reference management.
- `directives/range.js` (safe): No malicious patterns detected
- `directives/ref.js` (safe): This is the standard Lit library ref directive; it contains no malicious patterns, network calls, credential access, or dynamic code execution.
- `directives/repeat.js` (safe): No malicious patterns detected; the file is a legitimate minified implementation of the lit-html repeat directive.
- `directives/style-map.js` (safe): This is the standard Lit `styleMap` directive from the official lit-html package with no malicious patterns detected.
- `directives/template-content.js` (safe): This is a legitimate Lit library directive for rendering template content with no malicious patterns detected.
- `directives/unsafe-mathml.js` (safe): No malicious patterns detected; the file is a small, readable Lit directive extending UnsafeHTMLDirective with no network, filesystem, process, or dynamic execution behavior.
- `directives/unsafe-svg.js` (safe): This is a legitimate Lit unsafeSVG directive from Google's lit-html library with no malicious patterns detected.
- `directives/until.js` (safe): This is the standard Lit 'until' directive from the official lit-html package, containing only asynchronous rendering logic with no malicious patterns.
- `directives/when.js` (safe): No malicious patterns detected
- `is-server.js` (safe): No malicious patterns detected
- `lit-html.js` (safe): No malicious patterns detected in this minified lit-html library; it is a legitimate Google rendering library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious network/file/process operations.
- `node/async-directive.js` (safe): No malicious patterns detected; this is a legitimate Google Lit library file implementing an async directive with no external network, filesystem, or process activity.
- `node/development/async-directive.js` (safe): This is a legitimate Lit library file implementing AsyncDirective connection state management with no malicious patterns detected.
- `node/development/directive-helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directive.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/async-append.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/async-replace.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/cache.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/choose.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/class-map.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/guard.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/if-defined.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/join.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/keyed.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/live.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/map.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/private-async-helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/range.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/ref.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/repeat.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/style-map.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/unsafe-mathml.js` (safe): This file defines a lit-html UnsafeMathMLDirective that intentionally renders unsanitized MathML (documented as unsafe by design), but contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, dynamic execution, or install-time behavior.
- `node/development/directives/until.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/directives/when.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/is-server.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/lit-html.js` (safe): No malicious patterns detected; this is the official Lit library with standard template rendering, sanitization, and debugging code.
- `node/development/polyfill-support.js` (safe): The code is a legitimate lit-html polyfill for ShadyCSS/ShadyDOM compatibility, with no malicious patterns such as data exfiltration, dynamic code execution, or file system manipulation.
- `node/development/private-ssr-support.js` (safe): No malicious patterns detected in this Lit private SSR support module, which only contains legitimate internal framework utilities.
- `node/development/static.js` (safe): This is legitimate Lit library source code implementing documented static value support; the unsafe behaviors are intentional, clearly documented, and not malicious.
- `node/directive-helpers.js` (safe): This is a minified but non-obfuscated excerpt from the Lit library (Google LLC, BSD-3-Clause) containing only template rendering helpers with no malicious patterns.
- `node/directive.js` (safe): No malicious patterns detected
- `node/directives/async-append.js` (safe): This is a legitimate Lit async-append directive, containing no malicious patterns, network activity, filesystem access, or obfuscated code.
- `node/directives/async-replace.js` (safe): This is the legitimate Lit AsyncReplace directive from Google's lit-html library with no malicious patterns detected.
- `node/directives/cache.js` (safe): This is the official lit-html cache directive from Google's Lit library; no malicious patterns, exfiltration, obfuscation, or dangerous operations detected.
- `node/directives/choose.js` (safe): No malicious patterns detected; the code is a simple utility function with no security concerns
- `node/directives/class-map.js` (safe): No malicious patterns detected; this is the standard Lit classMap directive from Google's lit-html library.
- `node/directives/guard.js` (safe): This is the standard `guard` directive from the Lit library (Google), containing no malicious patterns, no network/filesystem access, and no dynamic code execution.
- `node/directives/if-defined.js` (safe): The file is a small, legitimate Lit library directive that maps undefined/null values to a 'nothing' sentinel, with no malicious patterns detected.
- `node/directives/join.js` (safe): No malicious patterns detected
- `node/directives/keyed.js` (safe): No malicious patterns detected; the file is a legitimate Lit directive for keyed rendering.
- `node/directives/live.js` (safe): No malicious patterns detected; this is the standard Lit 'live' directive implementation with only internal imports and no external data access or code execution.
- `node/directives/map.js` (safe): No malicious patterns detected
- `node/directives/private-async-helpers.js` (safe): No malicious patterns detected; the code is a legitimate Google Lit helper module for async iteration and weak reference management.
- `node/directives/range.js` (safe): No malicious patterns detected
- `node/directives/ref.js` (safe): This is the standard Lit library ref directive; it contains no malicious patterns, network calls, credential access, or dynamic code execution.
- `node/directives/repeat.js` (safe): No malicious patterns detected; the file is a legitimate minified implementation of the lit-html repeat directive.
- `node/directives/style-map.js` (safe): This is the standard Lit `styleMap` directive from the official lit-html package with no malicious patterns detected.
- `node/directives/template-content.js` (safe): This is a legitimate Lit library directive for rendering template content with no malicious patterns detected.
- `node/directives/unsafe-mathml.js` (safe): No malicious patterns detected; the file is a small, readable Lit directive extending UnsafeHTMLDirective with no network, filesystem, process, or dynamic execution behavior.
- `node/directives/unsafe-svg.js` (safe): This is a legitimate Lit unsafeSVG directive from Google's lit-html library with no malicious patterns detected.
- `node/directives/until.js` (safe): This is the standard Lit 'until' directive from the official lit-html package, containing only asynchronous rendering logic with no malicious patterns.
- `node/directives/when.js` (safe): No malicious patterns detected
- `node/is-server.js` (safe): No malicious patterns detected; the file simply exports a constant boolean indicating server-side execution.
- `node/lit-html.js` (safe): The file is the standard minified lit-html v3.3.1 rendering library with no malicious patterns such as exfiltration, credential harvesting, obfuscated payloads, process spawning, or install-time code.
- `node/polyfill-support.js` (safe): No malicious patterns detected; the code is a legitimate Lit polyfill support module with ShadyCSS/ShadyDOM handling and no exfiltration, obfuscation, or system access.
- `node/private-ssr-support.js` (safe): This is a legitimate Lit library module for SSR support with no malicious patterns detected
- `node/static.js` (safe): No malicious patterns detected; this is legitimate Lit static template caching code from Google with no network, filesystem, process, or dynamic execution activity.
- `polyfill-support.js` (safe): No malicious patterns detected; the file is the standard Lit polyfill-support.js with legitimate ShadyCSS polyfill logic.
- `private-ssr-support.js` (safe): This is a legitimate Lit library module for SSR support with no malicious patterns detected
- `static.js` (safe): No malicious patterns detected; this is legitimate Lit static template caching code from Google with no network, filesystem, process, or dynamic execution activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
