Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions npm/src/install.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -198,9 +198,13 @@ function extractFileFromTarball(tarballBuffer, filepath) {
8
)

const sizeInvalid = !Number.isFinite(fileSize) || Number.isNaN(fileSize) || fileSize < 0
if (sizeInvalid) {
const target = fileName === filepath ? filepath : fileName || '(unnamed entry)'
throw new Error(`Invalid size for ${target} in tarball`)
}

if (fileName === filepath) {
if (!Number.isFinite(fileSize) || Number.isNaN(fileSize) || fileSize < 0)
throw new Error(`Invalid size for ${filepath} in tarball`)
if (fileSize > MAX_BINARY_BYTES)
throw new Error(`Binary size for ${filepath} exceeds maximum allowed threshold`)
return tarballBuffer.subarray(offset, offset + fileSize)
Expand Down
Loading