# minimatch@3.1.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:29.000Z
- Files reviewed: 1
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/minimatch@3.1.5
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package minimatch@3.1.5 on Oct 6, 2026. An AI review of 1 source file produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dynamic regular expression construction

Finding ID: `NPS-7BA8CE8A487E`

File: `minimatch.js`

The code constructs regular expressions dynamically from user-supplied glob patterns. While this is inherent to the minimatch library's functionality, it can be a vector for ReDoS if not carefully bounded. The code includes a MAX_PATTERN_LENGTH check (1024*64) and a maxGlobstarRecursion limit (default 200) to mitigate this, but dynamic regex generation from external input remains a potential risk.

### [low] Use of new RegExp with user-controlled input

Finding ID: `NPS-1E5EE6552445`

File: `minimatch.js`

Throughout the parse and makeRe functions, user-supplied patterns are converted into RegExp objects. Although the library escapes special characters and limits pattern length, any vulnerability in the regex engine or bypass of the escaping logic could lead to denial of service or unexpected matching behavior.

### [low] Environment-dependent path separator handling

Finding ID: `NPS-DAEED8341CAD`

File: `minimatch.js`

The code conditionally requires the 'path' module and adjusts for Windows path separators. This is standard behavior for a cross-platform glob library and does not constitute a security concern by itself.

## Files reviewed

- `minimatch.js` (medium): The minimatch library is a legitimate glob matching utility with no evidence of malicious intent; it includes safeguards against ReDoS, though dynamic regex generation from user input is an inherent low-risk characteristic.

## Version ranges

None of the 3 scanned versions of minimatch are flagged high or critical. The latest scanned version, 10.2.6, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 10.2.5 – 10.2.6 (`>=10.2.5 <=10.2.6`): clean
- 5.1.9 – 10.2.4 (`>=5.1.9 <=10.2.4`): not scanned
- 3.1.5 (`3.1.5`): medium
- 3.1.2 – 3.1.4 (`>=3.1.2 <=3.1.4`): not scanned

## Scanned versions

- [10.2.6](https://security.togoder.click/npm/minimatch@10.2.6): safe, 2026-10-06T14:19:22.000Z
- [10.2.5](https://security.togoder.click/npm/minimatch@10.2.5): safe, 2026-10-06T14:23:17.000Z
- [3.1.5](https://security.togoder.click/npm/minimatch@3.1.5): medium, 2026-10-06T14:16:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
