# openid-client@5.7.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:41.000Z
- Files reviewed: 29
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/openid-client
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package openid-client@5.7.1 on Oct 6, 2026. An AI review of 29 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential SSRF via JWKS URI

Finding ID: `NPS-FCADD61B6B2C`

File: `lib/helpers/issuer.js:37`

No validation or restriction on the jwks_uri scheme or host. An attacker who can control issuer configuration could potentially direct requests to internal services.

### [low] Network request with dynamic URL

Finding ID: `NPS-D3B67D0F034A`

File: `lib/helpers/issuer.js:37`

The code performs an HTTP GET request to this.jwks_uri, which is a configurable issuer URL. This is normal behavior for JWKS fetching, but the URL is not validated against a whitelist, potentially allowing SSRF if attacker controls issuer configuration.

### [low] Network requests (benign)

Finding ID: `NPS-BD4BCC557AC1`

File: `lib/issuer.js`

The code makes outbound HTTPS requests to fetch OpenID Connect discovery documents and WebFinger metadata. These are standard, expected behaviors for an OpenID Connect client library and are not data exfiltration. The endpoints are derived from the user-supplied issuer URL and fixed Microsoft AAD discovery URLs.

### [low] Dynamic property definitions (benign)

Finding ID: `NPS-0DA58B032C40`

File: `lib/issuer.js:61`

Object.defineProperty is used to expose metadata keys as getters. This is used to build a public API object from trusted/validated response data, not for dynamic code execution. No eval, new Function, or similar constructs are present.

## Files reviewed

- `lib/helpers/issuer.js` (medium): No malicious patterns detected; the code is a legitimate JWKS keystore manager with standard network fetching, LRU caching, and in-flight request deduplication, though it lacks SSRF protections on the configurable jwks_uri.
- `lib/client.js` (safe): No malicious patterns detected; the code is a legitimate OpenID Connect client library.
- `lib/device_flow_handle.js` (safe): No malicious patterns detected
- `lib/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/base64url.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/client.js` (safe): The code is a legitimate OpenID client authentication helper that signs JWTs and constructs auth requests without any malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoor installation.
- `lib/helpers/consts.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/decode_jwt.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/deep_clone.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/defaults.js` (safe): No malicious patterns detected; the code is a standard deep object merging utility with prototype pollution protection.
- `lib/helpers/generators.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/is_key_object.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/is_plain_object.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/keystore.js` (safe): No malicious patterns detected
- `lib/helpers/merge.js` (safe): No malicious patterns detected; the code is a standard deep merge utility with explicit __proto__ and constructor guards to prevent prototype pollution.
- `lib/helpers/pick.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/process_response.js` (safe): The code performs normal HTTP response processing without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `lib/helpers/request.js` (safe): No malicious patterns detected
- `lib/helpers/unix_timestamp.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/weak_cache.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/webfinger_normalize.js` (safe): No malicious patterns detected; the code is a pure string normalization helper for WebFinger URIs with no network, filesystem, process, or dynamic code execution behavior.
- `lib/helpers/www_authenticate_parser.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/issuer.js` (safe): The module implements standard OpenID Connect issuer discovery and metadata handling; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or process spawning were detected.
- `lib/issuer_registry.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/passport_strategy.js` (safe): No malicious patterns detected
- `lib/token_set.js` (safe): No malicious patterns detected; the code is a legitimate JWT TokenSet utility handling expiration and claims parsing.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
