# yargs@18.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:25:37.000Z
- Files reviewed: 25
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/yargs@18.0.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package yargs@18.0.0 on Oct 6, 2026. An AI review of 25 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with external input

Finding ID: `NPS-E9D8AE43AB53`

File: `build/lib/utils/apply-extends.js`

The function uses import.meta.resolve() and _shim.require() to load modules based on the 'extends' property from a configuration object, which could potentially load malicious modules if the config is attacker-controlled. However, this is likely intentional functionality for extending configs.

### [medium] File system access

Finding ID: `NPS-3725904A191F`

File: `build/lib/utils/apply-extends.js`

Reads files using shim.readFileSync() based on paths derived from configuration. The path resolution uses shim.path.resolve() with a provided cwd, which could read files outside the package scope if paths contain directory traversal sequences.

### [low] Prototype pollution protection

Finding ID: `NPS-B8BF0BDBF290`

File: `build/lib/utils/apply-extends.js`

The mergeDeep function uses Object.assign and recursive merging but does not explicitly protect against prototype pollution (e.g., __proto__, constructor, prototype keys). An attacker-controlled config could potentially pollute Object.prototype.

### [low] Reading files and directories

Finding ID: `NPS-BDD4991EE576`

File: `lib/platform-shims/esm.mjs:13`

The module imports readFileSync and readdirSync from node:fs and exports them. This provides file system access to consumers of this module. While not malicious by itself, it could be a vector if the library is used by untrusted code. The y18n initialization also reads locale files from a resolved path outside the package's immediate directory (../../../locales), which is a relative path traversal outside the package scope. However, this is a common pattern for i18n libraries and the updateFiles option is set to false, preventing writes.

### [low] Path traversal / directory traversal in mainFilename computation

Finding ID: `NPS-A7D370047B0D`

File: `lib/platform-shims/esm.mjs:16`

The code computes mainFilename by taking __dirname and truncating it at the last occurrence of 'node_modules'. This logic assumes the package is installed inside node_modules. If the package is installed outside node_modules or in a symlinked environment (e.g., pnpm, yarn PnP, or globally), mainFilename may resolve to an unexpected path or be empty. This is not directly malicious but could lead to incorrect behavior or information disclosure about the filesystem structure. It also reveals the package expects to run within a specific directory structure.

### [low] Dynamic module loading / require creation

Finding ID: `NPS-76184522C2E0`

File: `lib/platform-shims/esm.mjs:17`

The code uses createRequire to create a require function relative to the current module. This is a common pattern in ESM modules to access CommonJS modules. While dynamic require can be a red flag for dynamic code execution, here it is used statically and does not accept external input. It is exported as part of the default object, which could be misused by consumers, but the module itself does not perform any dynamic loading with computed paths.

### [low] Environment variable access

Finding ID: `NPS-370B0831C6AC`

File: `lib/platform-shims/esm.mjs:22`

The exported getEnv function allows reading arbitrary environment variables via process.env[key]. While this is a common utility, it could be leveraged by an attacker if the consumer of this module passes untrusted input to getEnv, potentially exposing sensitive environment variables. However, this is a standard pattern in many CLI libraries and not inherently malicious.

### [low] Caller file resolution with get-caller-file

Finding ID: `NPS-55BE5AAD1671`

File: `lib/platform-shims/esm.mjs:58`

The getCallerFile function uses getCallerFile(3) to determine the calling file and normalizes file:// URLs. This is a common pattern for libraries that need to resolve paths relative to the caller. It does not execute code or access sensitive information directly, but it does inspect the call stack, which could be used for reconnaissance if the library is compromised. In this context, it appears benign.

## Files reviewed

- `build/lib/utils/apply-extends.js` (medium): The code implements configuration extension with file and module loading based on user-supplied config, presenting potential risks if input is not validated, but no overtly malicious patterns like exfiltration or command execution are present.
- `lib/platform-shims/esm.mjs` (medium): The code is a platform shim for an ESM environment, providing common utilities and imports; no overtly malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution were detected, but it does expose environment variable access, file system operations, and dynamic require creation which could be misused by consumers.
- `browser.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/argsert.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/command.js` (safe): No malicious patterns detected
- `build/lib/completion-templates.js` (safe): This file contains static shell completion script templates with placeholder substitutions and no executable, network, or filesystem-mutating code.
- `build/lib/completion.js` (safe): No malicious patterns detected
- `build/lib/middleware.js` (safe): No malicious patterns detected; the code implements yargs middleware management with no network, filesystem, process, or dynamic code execution activity.
- `build/lib/parse-command.js` (safe): No malicious patterns detected
- `build/lib/typings/common-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/typings/yargs-parser-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/usage.js` (safe): No malicious patterns detected; the code is a standard usage/help formatting module for the yargs CLI library with no network, credential, process spawning, or obfuscated behavior.
- `build/lib/utils/is-promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/levenshtein.js` (safe): No malicious patterns detected
- `build/lib/utils/maybe-async-result.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/obj-filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/process-argv.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/utils/set-blocking.js` (safe): No malicious patterns detected
- `build/lib/utils/which-module.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/lib/validation.js` (safe): No malicious patterns detected; the file contains standard yargs argument-validation logic without exfiltration, obfuscation, or dynamic code execution.
- `build/lib/yargs-factory.js` (safe): No malicious patterns detected; this is a legitimate yargs command-line argument parsing library factory with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `build/lib/yerror.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/helpers.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform-shims/browser.mjs` (safe): No malicious patterns detected

## Version ranges

None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 18.0.0 (`18.0.0`): medium (Dynamic module loading with external input +1 more)
- 17.7.2 – 17.7.3 (`>=17.7.2 <=17.7.3`): not scanned
- 15.4.1 – 16.2.0 (`>=15.4.1 <=16.2.0`): medium (dynamic module loading from external URL +4 more)
- 7.1.2 (`7.1.2`): not scanned

## Scanned versions

- [18.0.0](https://security.togoder.click/npm/yargs@18.0.0): medium, 2026-10-06T14:25:37.000Z
- [16.2.0](https://security.togoder.click/npm/yargs@16.2.0): medium, 2026-10-06T14:14:47.000Z
- [15.4.1](https://security.togoder.click/npm/yargs@15.4.1): medium, 2026-10-04T16:47:06.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
