Key details

  1. tinyjs 0.47.1 was released on October 4, 2026 and fixes malformed messages bypassing the api capability gate.
  2. The project says apps that wrap a site or use api.origins should update.
  3. 0.47.0 closed a CORS-open proxy path that could expose arbitrary sites or local-network URLs and stopped sensitive clipboard/keychain values appearing in debug traces.
  4. 0.46.0 fixed privileged file-window behavior, cross-user Windows pipes and Linux iframe origin confusion.
  5. 0.42.3 fixed launcher command injection that could reach shell execution through AppleScript on macOS.
  6. tinyjs uses native system webviews and describes typical shipped app size as about 6MB; Windows and Linux are beta.

What builders should take away

  1. If you ship tinyjs wrappers or configure api.origins, update to 0.47.1 rather than treating the releases as optional feature updates.
  2. Audit webview-to-native bridges as security boundaries: malformed RPC, iframe origin attribution and navigation policies deserve adversarial testing.
  3. Do not assume localhost or local IPC is automatically private on multi-user machines; bind identity and authenticate peers explicitly.
  4. Redact secrets in debug tooling because diagnostic paths often bypass the assumptions applied to production UI.
  5. For young runtimes, read several adjacent changelog releases rather than only the latest patch; security fixes can be distributed across a rapid hardening sequence.

What changed

tinyjs shipped a cluster of security releases between September 28 and October 4, 2026, including versions 0.46.0, 0.47.0 and 0.47.1. The latest fix blocks malformed page messages from bypassing the runtime’s API capability gate and executing with the app’s permissions or triggering its event handlers. The same audit cycle fixed a CORS-open media proxy that could expose arbitrary web or local-network URLs, privileged file:// window paths, cross-user Windows named-pipe exposure, Linux iframe origin confusion, sensitive debug traces and other boundary failures. An earlier September 29 fix closed a newline injection in page-controlled window IDs that could become launcher commands and, on macOS, execute shell commands through AppleScript.

Why it matters

tinyjs deliberately gives a JavaScript backend full system access while rendering the frontend in the operating system’s native webview. That makes its origin and capability boundary the security-critical part of the architecture, especially for apps wrapping hosted websites or embedding third-party frames. The project explicitly tells users of wrapped sites or api.origins to update to 0.47.1. This is also a useful small-project story because the releases show an early runtime rapidly tightening its threat model after external review rather than treating security issues as isolated bugs.

The latest bug bypassed the API gate itself

In 0.47.1, tinyjs changed all three platform launchers so malformed page messages are dropped before reaching the backend. The project says a restricted wrapped page or iframe could previously craft a message that bypassed the api gate, ran with the application’s permissions or invoked the application’s own event handlers. For a runtime built around controlled page-to-native RPC, that is a material boundary failure.

The audit found more than one route across the boundary

Version 0.47.0 restricted tiny.proxyURL after the project found that its CORS-open media proxy could fetch arbitrary HTTP(S) and local-network URLs for any page able to reach it. The same release routes external URL schemes through an explicit navigation policy, changes the updater so the tinyjs website no longer supplies executable installer code on every update, and redacts clipboard and keychain values from debug traces.

Local-machine isolation also needed work

Version 0.46.0 fixed a window-opening path that could turn a hostile page into a privileged local file window. On Windows it made single-instance and private app/window pipes user-specific and authenticated so another local account could not intercept OAuth callbacks, file paths or application traffic. On Linux it tightened iframe message handling so a cross-origin frame could not inherit the trusted top page’s API origin.

A page-controlled newline could become a shell command on macOS

Version 0.42.3 fixed a launcher command-injection issue in window IDs. Newlines could split the runtime’s launcher protocol and make the second line execute as a command. The project says the injection worked across platforms and that on macOS the reachable command set included AppleScript, allowing shell-command execution as the current user.

The project is small by design and still maturing

tinyjs uses the platform webview rather than bundling Chromium and says shipped apps are around 6MB. macOS is described as stable while Windows and Linux remain beta. The same minimal architecture that makes the runtime attractive also concentrates trust in a small launcher/RPC surface, making the recent audit and update cadence especially relevant to early adopters.

What to watch next

  • Whether tinyjs publishes formal security advisories or CVE identifiers for the reported issues.
  • Further findings from the external audit credited to @slabbdev.
  • Whether Windows and Linux move out of beta after the current cross-platform security hardening.
  • Any compatibility changes required by tighter api.origins, proxy or navigation policies.

Still unclear

  • The impact descriptions come from the tinyjs project changelog and linked reporter issues; there is not yet a separate public security advisory for every fix.
  • The project does not publish install-base data, so the number of affected applications is unknown.
  • Some vulnerabilities require specific configurations such as wrapped sites, permissive API exposure or local multi-user conditions.
  • Windows and Linux are explicitly beta, so their security and compatibility surface is still evolving.

Sources

Direct reading behind this dossier.

3 sources
tinyjs changelog
tinyjs official changelog

Primary source for versions 0.47.1, 0.47.0, 0.46.0 and the preceding security-hardening releases.

Security audit issue #30
tinyjs GitHub issue report

Reporter/audit context linked by the project changelog for the October security fixes.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment