Togoder security

npm package security report

multer@1.4.5-lts.2 security report

Risky patterns found that deserve a look.

Needs review Version 1.4.5-lts.2 Files reviewed 8 Size 13.0 KB Scanned

Summary

Togoder Security scanned the npm package multer@1.4.5-lts.2 on Oct 4, 2026. An AI review of 8 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
1
low

Findings 4

medium

Unsafe default destination

NPS-0227E5E8810A

The default destination for uploaded files is os.tmpdir(), a world-writable shared directory. Uploaded files may be readable, writable, or replaceable by other local users or processes, potentially leading to information disclosure or symlink-style attacks.

storage/disk.js:15
medium

Path handling relies on caller-supplied filename

NPS-58E5649839CE

The getFilename function can be overridden by caller-provided opts.filename, and getDestination can be overridden by opts.destination. If these come from untrusted configuration, path.join(destination, filename) could allow path traversal or writing outside intended directories. No validation or normalization is performed.

storage/disk.js:22
medium

Arbitrary file deletion

NPS-06384B87C909

_removeFile accepts a file object and deletes file.path via fs.unlink without verifying that the path is within an expected upload directory. If a caller can control or corrupt the file object, this could delete arbitrary files accessible to the process.

storage/disk.js:66
low

Synchronous directory creation

NPS-4420135E39FA

mkdirp.sync(opts.destination) performs blocking filesystem operations at construction time. While not inherently malicious, it can be abused to create directories at attacker-controlled paths if opts.destination is untrusted.

storage/disk.js:20

Files reviewed

FileVerdictWhat the reviewer saw
storage/disk.js medium The code is a typical multer DiskStorage implementation with no clear exfiltration or backdoor, but it has security weaknesses around shared temp directories, unvalidated paths, and arbitrary file deletion.
index.js safe No malicious patterns detected; this is a standard multer file upload middleware implementation with no exfiltration, dynamic execution, or suspicious behavior.
lib/counter.js safe Cleared by Jev triage; no further analysis needed
lib/file-appender.js safe No malicious patterns detected; the code is a standard multipart file upload placeholder manager with no network, filesystem, or execution threats.
lib/make-middleware.js safe No malicious patterns detected
lib/multer-error.js safe Cleared by Jev triage; no further analysis needed
lib/remove-uploaded-files.js safe No malicious patterns detected
storage/memory.js safe No malicious patterns detected; the code is a simple in-memory storage implementation using concat-stream to buffer file uploads.

Frequently asked questions

Is multer safe to use?

No confirmed malware was found in multer@1.4.5-lts.2, but the review flagged 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does multer contain malware?

No malware was identified in multer@1.4.5-lts.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was multer checked?

Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan multer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in multer@1.4.5-lts.2, cost nothing.

Related security reports