Intel

AIKIDO-2025-10095

effect is vulnerable to Uncaught Exception

Uncaught Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 14, 2025

18

Low Risk

This Affects:

JSeffect
2.0.0 - 3.12.11
Fixed in 3.12.12
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to uncaught exceptions due to tapOutput allowing an output type that was not properly inferred, leading to potential runtime errors. In the patched version, TypeScript correctly detects type mismatches at compile time, preventing unexpected crashes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

effect is vulnerable to Uncaught Exception in versions 2.0.0 - 3.12.11.

How to fix this

Upgrade the effect library to the patch version.