# tinyexec@1.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:41.000Z
- Files reviewed: 1
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/tinyexec
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tinyexec@1.3.0 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Process Spawning

Finding ID: `NPS-1C791858DD1B`

File: `dist/main.mjs:1`

The module is a cross-platform process execution library that wraps child_process.spawn/spawnSync. It intentionally spawns arbitrary commands and shell processes (cmd.exe on Windows) based on caller input. While this is the package's stated purpose, it exposes a powerful API surface that can be abused by callers to execute arbitrary system commands.

### [medium] Shell Command Construction

Finding ID: `NPS-D0AB814613A6`

File: `dist/main.mjs:86`

On Windows, normalizeSpawnCommand constructs a cmd.exe invocation string by joining command and arguments with spaces and escaping meta characters. Bugs or bypasses in this escaping could lead to command injection if untrusted input is passed to exec/execSync.

### [low] Environment Variable Manipulation

Finding ID: `NPS-F25E5ED224FE`

File: `dist/main.mjs:32`

computeEnv reads and modifies the process environment, including injecting node_modules/.bin paths and the Node executable directory into PATH. This could cause unintended binaries to be resolved/executed if the working directory contains a malicious node_modules/.bin.

### [low] Dynamic Command Resolution

Finding ID: `NPS-A9F356191771`

File: `dist/main.mjs:108`

resolveCommand resolves the target command by traversing PATH and PATHEXT and reading files (statSync, openSync, readSync) to detect shebangs. This enables execution of resolved binaries and can be influenced by attacker-controlled environment or working directory.

## Files reviewed

- `dist/main.mjs` (medium): This is a legitimate cross-platform process execution library (similar to execa) that spawns arbitrary child processes and constructs shell commands; no direct malicious behavior (exfiltration, credential theft, obfuscation, backdoors) is present, but its command-execution capabilities warrant caution when used with untrusted input.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
