# yargs@15.4.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:47:06.000Z
- Files reviewed: 18
- Findings: 2 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/yargs@15.4.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package yargs@15.4.1 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading from user-controlled input

Finding ID: `NPS-A35BC1EE7308`

File: `build/lib/apply-extends.js:42`

The function calls require.resolve(config.extends) and require(config.extends) where config.extends is taken from an arbitrary configuration object. If the input is attacker-controlled, this can load arbitrary Node.js modules or execute code from unintended locations. While typical for config extend features (yargs), it represents a code execution surface.

### [medium] Dynamic module loading

Finding ID: `NPS-F180227B97EE`

File: `build/lib/command.js:110`

The addDirectory function uses require-directory to dynamically require modules from a directory at runtime. While this is a legitimate yargs feature for loading command modules, it can be abused to load malicious modules if the directory path is attacker-controlled or if the package is installed in an untrusted environment.

### [low] File system read outside package scope

Finding ID: `NPS-D20D42E832BA`

File: `build/lib/apply-extends.js:63`

Uses fs.readFileSync(pathToDefault, 'utf8') to read arbitrary JSON/rc files resolved from config.extends. Path traversal or malicious configs could read sensitive files if the path is attacker-controlled, though JSON.parse limits impact.

### [low] Path manipulation

Finding ID: `NPS-3DAC2526899F`

File: `build/lib/command.js:122`

The commandFromFilename function uses path.basename and path.extname to derive command names from filenames. This is standard behavior but could be used to infer module locations when combined with whichModule.

### [low] Dynamic code execution

Finding ID: `NPS-6899A29E60BA`

File: `build/lib/command.js:213`

The builder callback is invoked with a yargs instance, allowing arbitrary code execution when a command is run. This is expected behavior for a command-line parser library, but the callback could contain malicious code if the package is compromised.

### [low] environment variable access

Finding ID: `NPS-BE3DDF6C9574`

File: `build/lib/completion.js:26`

Reads process.env.SHELL and process.env.ZSH_NAME to detect the user's shell for completion script generation. This is a benign, common pattern in CLI completion libraries and does not involve credential harvesting or exfiltration.

### [low] dynamic function invocation

Finding ID: `NPS-E4FC518D1708`

File: `build/lib/completion.js:39`

Calls a user-supplied completionFunction with parsed argv/current input. The function is registered via registerFunction by the consuming application, not evaluated from strings or external input. No eval, new Function, or dynamic code execution present.

## Files reviewed

- `build/lib/apply-extends.js` (medium): Legitimate configuration extension logic, but uses dynamic require/require.resolve and file reads driven by configuration input, which could enable code execution or file disclosure if untrusted configs are supplied.
- `build/lib/command.js` (medium): The code appears to be a legitimate implementation of yargs command parsing with standard dynamic module loading and callback execution patterns, but the dynamic require-directory usage and builder callbacks could pose a risk if the package is compromised.
- `build/lib/argsert.js` (safe): No malicious patterns detected; the code is a straightforward argument validation utility for yargs with no network, filesystem, process, or dynamic execution activity.
- `build/lib/common-types.js` (safe): No malicious patterns detected
- `build/lib/completion-templates.js` (safe): Static shell completion template strings for yargs with no executable, network, or exfiltration behavior.
- `build/lib/completion.js` (safe): This is a legitimate yargs shell-completion module with no malicious patterns; environment reads and callback invocations are standard and benign.
- `build/lib/is-promise.js` (safe): No malicious patterns detected
- `build/lib/levenshtein.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/middleware.js` (safe): No malicious patterns detected
- `build/lib/obj-filter.js` (safe): No malicious patterns detected
- `build/lib/parse-command.js` (safe): No malicious patterns detected; the code is a simple command-line argument parser with no network, filesystem, process, or dynamic execution behavior.
- `build/lib/process-argv.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/usage.js` (safe): No malicious patterns detected; the file is a legitimate yargs usage/help rendering module with no network, credential, obfuscation, or process-spawning behavior.
- `build/lib/validation.js` (safe): No malicious patterns detected; the code is a standard argument validation module from the yargs library with no exfiltration, credential harvesting, obfuscation, or unauthorized execution.
- `build/lib/yargs.js` (safe): This is the legitimate yargs CLI argument parsing library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected.
- `build/lib/yerror.js` (safe): No malicious patterns detected
- `index.js` (safe): No malicious patterns detected; the code is a standard yargs singleton wrapper with no suspicious behavior.
- `yargs.js` (safe): No malicious patterns detected

## Version ranges

None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 18.0.0 (`18.0.0`): medium (Dynamic module loading with external input +1 more)
- 17.7.2 – 17.7.3 (`>=17.7.2 <=17.7.3`): not scanned
- 15.4.1 – 16.2.0 (`>=15.4.1 <=16.2.0`): medium (dynamic module loading from external URL +4 more)
- 7.1.2 (`7.1.2`): not scanned

## Scanned versions

- [18.0.0](https://security.togoder.click/npm/yargs@18.0.0): medium, 2026-10-06T14:25:37.000Z
- [16.2.0](https://security.togoder.click/npm/yargs@16.2.0): medium, 2026-10-06T14:14:47.000Z
- [15.4.1](https://security.togoder.click/npm/yargs@15.4.1): medium, 2026-10-04T16:47:06.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
