From 4547cf321904b6714f4f47605649c7820142f056 Mon Sep 17 00:00:00 2001 From: metsw24-max Date: Mon, 15 Jun 2026 14:31:43 +0530 Subject: [PATCH] validate recomb matrix entries are numbers --- lib/operation.mjs | 5 ++++- test/unit/recomb.js | 6 ++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/lib/operation.mjs b/lib/operation.mjs index 7d802c2ec..10e2aa439 100644 --- a/lib/operation.mjs +++ b/lib/operation.mjs @@ -862,10 +862,13 @@ function recomb (inputMatrix) { if (inputMatrix.length !== 3 && inputMatrix.length !== 4) { throw is.invalidParameterError('inputMatrix', '3x3 or 4x4 array', inputMatrix.length); } - const recombMatrix = inputMatrix.flat().map(Number); + const recombMatrix = inputMatrix.flat(); if (recombMatrix.length !== 9 && recombMatrix.length !== 16) { throw is.invalidParameterError('inputMatrix', 'cardinality of 9 or 16', recombMatrix.length); } + if (!recombMatrix.every(is.number)) { + throw is.invalidParameterError('inputMatrix', 'array of numbers', recombMatrix); + } this.options.recombMatrix = recombMatrix; return this; } diff --git a/test/unit/recomb.js b/test/unit/recomb.js index 4b600c16d..52c9778fb 100644 --- a/test/unit/recomb.js +++ b/test/unit/recomb.js @@ -164,5 +164,11 @@ suite('Recomb', () => { sharp(fixtures.inputJpg).recomb([[1, 2, 3, 4], [5, 6, 7, 8]]); }); }); + test('non-numeric entries', (t) => { + t.plan(1); + t.assert.throws(() => { + sharp(fixtures.inputJpg).recomb([['a', 'b', 'c'], [1, 2, 3], [4, 5, 6]]); + }); + }); }); });