# @napi-rs/wasm-runtime@1.1.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:37.000Z
- Files reviewed: 4
- Findings: 6 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@napi-rs/wasm-runtime@1.1.4
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @napi-rs/wasm-runtime@1.1.4 on Oct 6, 2026. An AI review of 4 source files produced 6 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsafe deserialization / prototype pollution

Finding ID: `NPS-6D6A903AB04A`

File: `dist/fs-proxy.cjs:168`

The decodeValue function reconstructs objects from JSON and calls Object.setPrototypeOf(obj, memfs[ctor].prototype) based on an attacker-controlled '__constructor__' property. An attacker controlling the postMessage payload can influence the prototype chain of deserialized objects, potentially leading to prototype pollution or unexpected behavior. The code also looks up globalThis[name] for error reconstruction, which can resolve arbitrary global constructors.

### [medium] Attacker-controlled function invocation via Proxy

Finding ID: `NPS-6996EC660A4C`

File: `dist/fs-proxy.cjs:265`

createFsProxy returns a Proxy whose get trap returns a function that invokes fs[type] with attacker-supplied arguments delivered via postMessage. The 'type' property comes from the message and is used directly as a key on the memfs object, so any property/method present on fs can be invoked by a message sender. This is an IPC trust boundary issue if messages can come from untrusted contexts (e.g., cross-origin iframes, workers, or injected scripts).

### [medium] prototype manipulation via JSON deserialization

Finding ID: `NPS-C74C68D807CA`

File: `fs-proxy.js:176`

The decodeValue function reads an `__constructor__` property from parsed JSON and calls `Object.setPrototypeOf(obj, memfs[ctor].prototype)`. A crafted message could set an object's prototype to an arbitrary constructor's prototype, leading to prototype pollution or type confusion in the receiving context.

### [medium] unsanitized message channel dispatch

Finding ID: `NPS-141A871EF5A4`

File: `fs-proxy.js:247`

The onMessage handler trusts the structure of `e.data.__fs__` and directly uses `sab`, `type`, and `payload` from it. There is no validation that the sender is authorized or that the SharedArrayBuffer dimensions match expectations, enabling malformed input to reach encode/decode logic.

### [medium] dynamic property access on filesystem object

Finding ID: `NPS-0ADDACF5BF74`

File: `fs-proxy.js:259`

The createOnMessage function resolves an arbitrary method name from message data via `const fn = fs[type]` and invokes it with attacker-controlled arguments (`fn.apply(fs, payload)`). This allows any method of the memfs instance to be called remotely, potentially exposing unintended filesystem operations if the message channel is reachable by untrusted input.

### [medium] synchronous blocking / denial of service

Finding ID: `NPS-4B2EFB3D0F51`

File: `fs-proxy.js:325`

createFsProxy uses `Atomics.wait` on the main thread, blocking the event loop until a response is posted. If the counterpart is missing, compromised, or slow, this can hang the entire runtime indefinitely.

### [low] Untrusted data passed to JSON.parse / BigInt / TextDecoder

Finding ID: `NPS-C2FD84509A3B`

File: `dist/fs-proxy.cjs:132`

decodeValue parses payloads received via postMessage without validation, including JSON.parse, BigInt conversion, and Float64Array/Int32Array reinterpretation. Malformed or hostile payloads could trigger unexpected exceptions or resource consumption in the consumer.

### [low] error constructor injection

Finding ID: `NPS-EDE0D0777E7A`

File: `fs-proxy.js:189`

In decodeValue, `const ErrorConstructor = globalThis[name] || Error` uses the untrusted `__error__` string from the payload. Although it falls back to Error, arbitrary global constructors can be invoked, and properties are copied from the decoded object onto the new error instance, which could be abused for object injection.

### [low] Potential dynamic module loading / import-time behavior

Finding ID: `NPS-C66A1D72919B`

File: `runtime.cjs:1`

The file requires '@emnapi/core', '@emnapi/runtime', '@tybys/wasm-util', and a local './dist/fs-proxy.cjs' module at import time. While these are legitimate-looking dependencies for WebAssembly/N-API interop, loading a local dist file and re-exporting its functions (createFsProxy, createOnMessage) means the package executes whatever logic is in that file upon import. The referenced dist/fs-proxy.cjs is not shown, so its behavior cannot be verified; it could contain filesystem proxying, network access, or other sensitive operations. This warrants caution rather than a clean safe verdict.

## Files reviewed

- `dist/fs-proxy.cjs` (medium): The file implements a SharedArrayBuffer-based synchronous RPC bridge to memfs with no obvious exfiltration, credential harvesting, or code execution, but the deserialization and proxy dispatch paths trust postMessage payloads and reconstruct object prototypes based on attacker-influenced fields, warranting caution.
- `fs-proxy.js` (medium): The file implements a SharedArrayBuffer-based RPC proxy for memfs that deserializes untrusted messages and dynamically invokes filesystem methods, creating prototype-pollution, method-injection, and denial-of-service risks if the message channel is exposed to untrusted input.
- `runtime.cjs` (medium): No overtly malicious code is visible in runtime.cjs itself, but it eagerly loads and re-exports local and third-party modules at import time, and the referenced fs-proxy implementation is not auditable here.
- `runtime.js` (safe): The file only contains static re-exports from local and known @emnapi/@tybys packages, with no executable code, dynamic imports, or suspicious patterns.

## Version ranges

None of the 2 scanned versions of @napi-rs/wasm-runtime are flagged high or critical. The latest scanned version, 1.2.4, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.2.4 (`1.2.4`): medium (prototype pollution / unsafe deserialization +4 more)
- 1.1.6 – 1.2.2 (`>=1.1.6 <=1.2.2`): not scanned
- 1.1.4 (`1.1.4`): medium (Unsafe deserialization / prototype pollution +4 more)
- 0.2.4 – 0.2.12 (`>=0.2.4 <=0.2.12`): not scanned

## Scanned versions

- [1.2.4](https://security.togoder.click/npm/@napi-rs/wasm-runtime@1.2.4): medium, 2026-10-06T14:11:21.000Z
- [1.1.4](https://security.togoder.click/npm/@napi-rs/wasm-runtime@1.1.4): medium, 2026-10-06T14:12:37.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
