tigris-image-optimization
Audited by Socket on Sep 13, 2026
3 alerts found:
Anomalyx3No clear malware, backdoor, credential theft, or suspicious exfiltration is present. The principal risks are unrestricted in-memory uploads, insufficient image validation, public exposure of uploaded content, incorrect content-type labeling, and timestamp-only object naming. Add upload and pixel limits, validate the decoded format and dimensions, handle missing files, generate collision-resistant keys, and make public access an explicit requirement rather than the default.
No clear malicious behavior is present. The code implements ordinary image upload, thumbnail generation, and public storage. The principal security concerns are unrestricted upload/resource consumption, lack of visible authentication and validation, trusting the client MIME type, predictable object names, and intentional public exposure of uploaded originals. File size and image dimensions should be limited, the actual file format should be validated, unique non-predictable keys should be used, and public access should be deliberate. The srcset URLs should be trusted and contextually escaped.
No evidence of intentional malware or supply-chain sabotage is present. The code implements ordinary image upload and transformation, but it has application-level security weaknesses: an unsanitized client filename is used in storage keys, uploads can overwrite colliding objects, image parsing may be vulnerable to resource-exhaustion inputs, and all outputs are public. The filename should be replaced with a server-generated identifier and the upload should be strictly validated before processing.