cad-viewer

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/viewer/packages/implicitjs/src/common/implicitHeadlessRenderEntry.js

This module primarily performs image rendering and GIF encoding, with no direct evidence of credential theft, data exfiltration, or malicious payload execution in the shown code. The dominant security concern is the dynamic loading of a cached implicit CAD runtime using an externally supplied URL (inputUrl), which could enable SSRF or remote asset/code inclusion depending on loadCachedImplicitCadModule’s allowlisting and execution model. Additionally, in browser contexts it exposes a global window entrypoint and may be susceptible to resource exhaustion if rendering dimensions/frame counts are not bounded.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Jun 23, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/earthtojake%2Ftext-to-cad%2Fcad-viewer%2F@40a5b2da9ce877bd3155f429a96c5ac109cb6f4fa7667f495900e8e53b87b2d1
Security Audit — socket — cad-viewer