# yargs@16.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:47.000Z
- Files reviewed: 26
- Findings: 1 high, 4 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/yargs@16.2.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package yargs@16.2.0 on Oct 6, 2026. An AI review of 26 source files produced 1 high, 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] dynamic module loading from external URL

Finding ID: `NPS-DD5FE9F9BBD7`

File: `lib/platform-shims/browser.mjs:3`

The file imports modules directly from 'https://unpkg.com/...' (cliui and yargs-parser). This bypasses the package registry and relies on a third-party CDN at runtime. If the CDN is compromised or the URL is tampered with, arbitrary malicious code could be injected. This is a supply chain risk and also violates typical package integrity expectations.

### [medium] Dynamic require with computed input

Finding ID: `NPS-DE8B7F7C6CCC`

File: `build/lib/utils/apply-extends.js:12`

The code calls require.resolve(config.extends) and require(config.extends) where config.extends comes from an external configuration file. If an attacker can control the config file contents, they could load arbitrary modules. While this is a legitimate feature of the 'extends' mechanism, it represents a dynamic module loading path that could be abused if untrusted configuration is processed.

### [medium] File system read outside package scope

Finding ID: `NPS-8ADE78B0E880`

File: `build/lib/utils/apply-extends.js:22`

The function reads configuration files from arbitrary paths resolved relative to cwd via shim.readFileSync(pathToDefault, 'utf8'). An attacker controlling the 'extends' value could read arbitrary JSON/rc files on the filesystem.

### [medium] top-level import execution

Finding ID: `NPS-1ACA70913B85`

File: `lib/platform-shims/browser.mjs:3`

Imports from external URLs execute code at module load time. This code runs on import without explicit user action, which could be leveraged for malicious purposes if the remote content is malicious or altered.

### [medium] external dependency version pinning via URL

Finding ID: `NPS-6B360ABD1A64`

File: `lib/platform-shims/browser.mjs:3`

The imports use unpinned or CDN-hosted versions (e.g., unpkg.com/cliui@7.0.1). While versioned, the CDN could serve different content than the original npm package, and there is no integrity verification (e.g., SRI hash). This increases risk of tampering.

### [low] Dynamic command execution via callback

Finding ID: `NPS-613632492F83`

File: `build/lib/completion.js`

The code invokes user-provided completion functions and command builders via `completionFunction(current, argv)` and `builder(y)`. This is expected behavior for a CLI completion library and does not represent a vulnerability, as the callbacks are supplied by the application using yargs, not from attacker-controlled input.

## Files reviewed

- `build/lib/utils/apply-extends.js` (medium): The code implements a legitimate config 'extends' feature but uses dynamic require and arbitrary file reads that could be abused if untrusted configuration input is processed.
- `lib/platform-shims/browser.mjs` (medium): The file contains no overt malicious behavior but uses dynamic imports from an external CDN at runtime, introducing supply chain and code integrity risks.
- `browser.mjs` (safe): No malicious patterns detected; the file is a standard yargs browser bootstrap with static imports and no dynamic or external code execution.
- `build/lib/argsert.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/command.js` (safe): No malicious patterns detected; the file contains standard command handling logic for the yargs argument parser library.
- `build/lib/completion-templates.js` (safe): The file contains only template strings for generating shell completion scripts for yargs, with no executable code, network calls, or credential access.
- `build/lib/completion.js` (safe): The file is part of the yargs CLI parsing library and implements shell completion logic without any data exfiltration, credential harvesting, obfuscated payloads, or other malicious patterns.
- `build/lib/middleware.js` (safe): No malicious patterns detected
- `build/lib/parse-command.js` (safe): No malicious patterns detected
- `build/lib/typings/common-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/typings/yargs-parser-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/usage.js` (safe): No malicious patterns detected; this is the standard yargs usage/help formatting module with no exfiltration, credential harvesting, obfuscation, or process/network activity.
- `build/lib/utils/is-promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/levenshtein.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/obj-filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/process-argv.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/set-blocking.js` (safe): No malicious patterns detected
- `build/lib/utils/which-module.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/validation.js` (safe): No malicious patterns detected; the file contains standard yargs argument validation logic without exfiltration, code execution, or suspicious behavior.
- `build/lib/yargs-factory.js` (safe): No malicious patterns detected; the code is the standard yargs command-line parser factory with expected option handling and no exfiltration, credential harvesting, or dynamic code execution.
- `build/lib/yerror.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/helpers.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.cjs` (safe): The code is a standard yargs entry point that initializes the CLI parser, exposes a singleton API, and contains no obfuscation, exfiltration, credential harvesting, or other malicious patterns.
- `index.mjs` (safe): No malicious patterns detected
- `lib/platform-shims/esm.mjs` (safe): No malicious patterns detected; the file is a legitimate ESM platform shim for yargs with no suspicious network, filesystem, or execution behavior.

## Version ranges

None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 18.0.0 (`18.0.0`): medium (Dynamic module loading with external input +1 more)
- 17.7.2 – 17.7.3 (`>=17.7.2 <=17.7.3`): not scanned
- 15.4.1 – 16.2.0 (`>=15.4.1 <=16.2.0`): medium (dynamic module loading from external URL +4 more)
- 7.1.2 (`7.1.2`): not scanned

## Scanned versions

- [18.0.0](https://security.togoder.click/npm/yargs@18.0.0): medium, 2026-10-06T14:25:37.000Z
- [16.2.0](https://security.togoder.click/npm/yargs@16.2.0): medium, 2026-10-06T14:14:47.000Z
- [15.4.1](https://security.togoder.click/npm/yargs@15.4.1): medium, 2026-10-04T16:47:06.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
