GHSA-wxr3-2hgv-qm8f
GitHub Security Advisory
node-twain vulnerable to Improper Check or Handling of Exceptional Conditions
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new twain.TwainSDK with a productName or productFamily, manufacturer, version.info property of length >= 34 chars leads to a buffer overflow vulnerability.
Affected Packages
npm
node-twain
Affected versions:
0
(last affected: 0.0.16)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.