# @napi-rs/wasm-runtime@1.2.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:21.000Z
- Files reviewed: 6
- Findings: 1 high, 4 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@napi-rs/wasm-runtime
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @napi-rs/wasm-runtime@1.2.4 on Oct 6, 2026. An AI review of 6 source files produced 1 high, 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] prototype pollution / unsafe deserialization

Finding ID: `NPS-3628160A5766`

File: `fs-proxy.js`

decodeValue reconstructs object prototypes based on a `__constructor__` field embedded in JSON payloads. An attacker controlling the message payload can set `__constructor__` to any key on memfs, and `Object.setPrototypeOf(obj, memfs[ctor].prototype)` is executed without validation. Combined with `globalThis[name]` lookup for `__error__`, this permits constructing arbitrary global objects from untrusted input, potentially enabling prototype pollution or unexpected object instantiation.

### [medium] Unvalidated dynamic property access on memfs

Finding ID: `NPS-17CD01894DAA`

File: `dist/fs-proxy.cjs:128`

decodeValue and loadConstructor use attacker-controlled JSON properties (__constructor__) to index into the memfs object via memfs[ctor].prototype. A crafted message could set ctor to values like '__proto__' or 'constructor', leading to prototype pollution or access to unintended object properties. While this is a message-passing boundary rather than direct external input, the values come from another context and are not validated against a whitelist of expected fs constructors.

### [medium] Prototype manipulation from serialized data

Finding ID: `NPS-FC7CB8DC1A48`

File: `dist/fs-proxy.cjs:129`

loadConstructor calls Object.setPrototypeOf(obj, memfs[ctor].prototype) using a string read from the deserialized payload. Combined with the __constructor__ field being written into arbitrary nested objects during encoding, this allows deserialized objects to have their prototype replaced based on data received over the message channel. This could be abused for prototype confusion or sandbox escape depending on what memfs contains.

### [medium] unsafe dynamic property access

Finding ID: `NPS-AC80B010781C`

File: `fs-proxy.js`

createFsProxy uses a Proxy get handler that returns a function invoking `fs[type]` where `type` is supplied by the caller via postMessage. If `type` is not a legitimate fs method name (e.g. 'constructor', 'toString', '__proto__'), the call may resolve to an unexpected function or cause errors. This is an uncontrolled dynamic dispatch pattern that can expose unintended object members.

### [medium] arbitrary global constructor invocation

Finding ID: `NPS-5479CE692CC0`

File: `fs-proxy.js`

In decodeValue, when `obj.__error__` is present, the code performs `globalThis[name]` and instantiates `new ErrorConstructor(obj.message)`. Since `name` is attacker-controlled, this can invoke arbitrary global constructors. While limited to constructors with a single argument, this is still an unsafe pattern driven by untrusted input.

### [low] Dynamic error constructor lookup

Finding ID: `NPS-0E2E3BC251A1`

File: `dist/fs-proxy.cjs:139`

When decoding error objects, the code does globalThis[name] where name comes from the serialized __error__ field. This resolves arbitrary global properties by name and constructs them with new ErrorConstructor(obj.message). While it falls back to Error and appears limited to constructing errors, resolving arbitrary globals from untrusted serialized data is a risky pattern that could be leveraged if globalThis is extended elsewhere.

### [low] SharedArrayBuffer synchronization with Atomics.wait

Finding ID: `NPS-612B6C9C3478`

File: `dist/fs-proxy.cjs:191`

The proxy uses SharedArrayBuffer and Atomics.wait to block until the worker responds. If the receiving side never notifies (e.g., due to a crash or malicious peer), the calling thread can hang indefinitely. There is no timeout, which could be abused for denial of service in a multi-tenant or untrusted-worker scenario.

### [low] unbounded recursive traversal

Finding ID: `NPS-9D29F4B1AAB4`

File: `fs-proxy.js`

storeConstructor and loadConstructor recursively walk Object.values of arbitrary objects without depth limits. Deeply nested or cyclic structures (partially mitigated by WeakSet) from untrusted input can cause stack exhaustion or excessive CPU usage, a potential denial-of-service vector.

### [low] payload size handling

Finding ID: `NPS-8FE71CA80374`

File: `fs-proxy.js`

encodeValue for type 6 (JSON) and type 4 (string) does not enforce the RESPONSE_PAYLOAD_SIZE limit before returning. writeResponsePayload throws on overflow, but in the success path this throw happens after partial state setup, and in the error path a fallback overflow handling exists. The JSON path is not explicitly bounded before serialization, allowing large in-memory strings to be produced before the size check.

### [low] Dynamic module resolution via re-export

Finding ID: `NPS-B69FF855A8B9`

File: `runtime.js`

The wildcard re-export of `@tybys/wasm-util` and named re-exports from local files (`./dist/emnapi-plugins.js`, `./fs-proxy.js`) mean that importing this module eagerly loads and exposes additional code paths not shown in this file. Without auditing those referenced modules, this file cannot be considered fully benign.

### [low] Wildcard re-export

Finding ID: `NPS-2DE520B06ECA`

File: `runtime.js:35`

The file contains `export * from '@tybys/wasm-util'`, which re-exports all members from an external dependency. This can unintentionally expose or propagate dangerous functions from that package and makes the public API surface non-explicit and harder to audit.

## Files reviewed

- `dist/fs-proxy.cjs` (medium): The fs-proxy module is a memfs RPC bridge with no obvious exfiltration, shell, or install-time code, but it deserializes attacker-influenced JSON and uses unvalidated strings to index memfs and globalThis for prototype/constructor restoration, creating prototype-pollution and object-confusion risks.
- `fs-proxy.js` (medium): This file is a message-passing FS proxy with no network, process, or filesystem exfiltration, but it contains unsafe deserialization and dynamic dispatch patterns that could be exploited if message payloads are not fully trusted.
- `runtime.js` (medium): No overt malicious behavior is present in this file, but wildcard and cross-file re-exports prevent a complete safety determination of the runtime's effective behavior.
- `dist/emnapi-plugins.cjs` (safe): The code is the legitimate @emnapi/core async-work and threadsafe-function plugin implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or unauthorized network/file/process activity.
- `dist/emnapi-plugins.js` (safe): The file contains standard @emnapi/core WebAssembly plugin implementations for async work and threadsafe functions with no malicious patterns, exfiltration, credential harvesting, or suspicious behavior detected.
- `runtime.cjs` (safe): No malicious patterns detected; this file only aggregates and re-exports legitimate WASI/emnapi runtime utilities from known dependencies and local relative modules.

## Version ranges

None of the 2 scanned versions of @napi-rs/wasm-runtime are flagged high or critical. The latest scanned version, 1.2.4, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.2.4 (`1.2.4`): medium (prototype pollution / unsafe deserialization +4 more)
- 1.1.6 – 1.2.2 (`>=1.1.6 <=1.2.2`): not scanned
- 1.1.4 (`1.1.4`): medium (Unsafe deserialization / prototype pollution +4 more)
- 0.2.4 – 0.2.12 (`>=0.2.4 <=0.2.12`): not scanned

## Scanned versions

- [1.2.4](https://security.togoder.click/npm/@napi-rs/wasm-runtime@1.2.4): medium, 2026-10-06T14:11:21.000Z
- [1.1.4](https://security.togoder.click/npm/@napi-rs/wasm-runtime@1.1.4): medium, 2026-10-06T14:12:37.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
