asset-manager
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/font-management.md
LOWAnomalyLOW
references/font-management.md
The code is intended to convert local TTF/OTF fonts and configure browser font loading. It contains no clear malicious behavior, but the use of shell-based exec with unescaped input paths is a substantive command-injection vulnerability when the input directory or its filenames are attacker-controlled. Use execFile or spawn with argument arrays, validate paths, and verify regular files before conversion.
Confidence: 98%Severity: 62%
Audit Metadata