Intel

AIKIDO-2025-10066

@napi-rs/canvas is vulnerable to Uncaught Exception

Uncaught Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

18

Low Risk

This Affects:

JS@napi-rs/canvas
0.0.1 - 0.1.65
Fixed in 0.1.66

TL;DR

Affected versions of this package are vulnerable to uncaught exceptions. A crash occurs when calling putImageData() with resize parameters, leading to an unhandled exception. This issue arises due to improper handling of input parameters during image manipulation, which can cause the application to terminate unexpectedly. If not properly mitigated, this vulnerability may result in service disruptions, potential Denial-of-Service (DoS) scenarios, or unintended application behavior when processing images.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@napi-rs/canvas is vulnerable to Uncaught Exception in versions 0.0.1 - 0.1.65.

How to fix this

Upgrade the @napi-rs/canvas library to the patch version.