# multer@1.4.5-lts.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:35:25.000Z
- Files reviewed: 8
- Findings: 3 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/multer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package multer@1.4.5-lts.2 on Oct 4, 2026. An AI review of 8 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsafe default destination

Finding ID: `NPS-0227E5E8810A`

File: `storage/disk.js:15`

The default destination for uploaded files is os.tmpdir(), a world-writable shared directory. Uploaded files may be readable, writable, or replaceable by other local users or processes, potentially leading to information disclosure or symlink-style attacks.

### [medium] Path handling relies on caller-supplied filename

Finding ID: `NPS-58E5649839CE`

File: `storage/disk.js:22`

The getFilename function can be overridden by caller-provided opts.filename, and getDestination can be overridden by opts.destination. If these come from untrusted configuration, path.join(destination, filename) could allow path traversal or writing outside intended directories. No validation or normalization is performed.

### [medium] Arbitrary file deletion

Finding ID: `NPS-06384B87C909`

File: `storage/disk.js:66`

_removeFile accepts a file object and deletes file.path via fs.unlink without verifying that the path is within an expected upload directory. If a caller can control or corrupt the file object, this could delete arbitrary files accessible to the process.

### [low] Synchronous directory creation

Finding ID: `NPS-4420135E39FA`

File: `storage/disk.js:20`

mkdirp.sync(opts.destination) performs blocking filesystem operations at construction time. While not inherently malicious, it can be abused to create directories at attacker-controlled paths if opts.destination is untrusted.

## Files reviewed

- `storage/disk.js` (medium): The code is a typical multer DiskStorage implementation with no clear exfiltration or backdoor, but it has security weaknesses around shared temp directories, unvalidated paths, and arbitrary file deletion.
- `index.js` (safe): No malicious patterns detected; this is a standard multer file upload middleware implementation with no exfiltration, dynamic execution, or suspicious behavior.
- `lib/counter.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/file-appender.js` (safe): No malicious patterns detected; the code is a standard multipart file upload placeholder manager with no network, filesystem, or execution threats.
- `lib/make-middleware.js` (safe): No malicious patterns detected
- `lib/multer-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/remove-uploaded-files.js` (safe): No malicious patterns detected
- `storage/memory.js` (safe): No malicious patterns detected; the code is a simple in-memory storage implementation using concat-stream to buffer file uploads.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
