# xmlhttprequest-ssl@2.1.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:46:48.000Z
- Files reviewed: 1
- Findings: 1 high, 3 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/xmlhttprequest-ssl
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package xmlhttprequest-ssl@2.1.2 on Oct 4, 2026. An AI review of 1 source file produced 1 high, 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Synchronous file read/write via child process spawn

Finding ID: `NPS-DC3D79D22FC8`

File: `lib/XMLHttpRequest.js:478`

In the synchronous branch of send(), the code builds a JavaScript string with user-controlled data and options and executes it via child_process.spawn with the '-e' flag. Untrusted input in settings.url, headers, or data could break out of the string and lead to arbitrary code execution in the spawned Node process.

### [medium] File system read outside package scope

Finding ID: `NPS-EE4C60DDDAA5`

File: `lib/XMLHttpRequest.js:260`

The file:// protocol handler allows reading arbitrary local files via fs.readFile/fs.readFileSync based on the supplied URL, without any path restriction.

### [medium] Insecure temp file handling

Finding ID: `NPS-1FC1B866CF17`

File: `lib/XMLHttpRequest.js:472`

The synchronous path writes to predictable filenames (.node-xmlhttprequest-content-<pid> and .node-xmlhttprequest-sync-<pid>) in the current working directory. This can allow symlink attacks or races where another process reads/tampers with content or blocks the busy-wait loop.

### [medium] Credential handling in spawned process

Finding ID: `NPS-E82786EEA9F8`

File: `lib/XMLHttpRequest.js:478`

Basic auth credentials (settings.user, settings.password) are serialized into the execString passed to spawn via JSON.stringify(options), exposing credentials in the process command line where they may be visible to other users on the system.

### [low] Custom header check bypass

Finding ID: `NPS-89EA8F5E15B4`

File: `lib/XMLHttpRequest.js:168`

setDisableHeaderCheck() allows callers to disable the forbidden request header check, potentially enabling header injection into requests (e.g., Host, Cookie).

## Files reviewed

- `lib/XMLHttpRequest.js` (medium): This XMLHttpRequest polyfill contains legitimate functionality but includes risky patterns: it spawns a Node child process with dynamically constructed code containing user-influenced data, uses predictable temp files, and exposes a bypass for header restrictions, creating potential for local code execution and credential leakage.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
