v1.8.1-alpha : WASM bindings and IDL sanitization
Pre-release
Pre-release
Changelog
v1.8.1-alpha — WASM bindings and IDL sanitization (2026-09-30)
Security release addressing PSIRT-3497 (code injection via crafted IDL). Also bundles all binding fixes and features that landed since v1.8.0-alpha, including new WebAssembly bindings, Node.js binding improvements, and C++ thread-safety options.
Upgrade is recommended for all users, especially anyone building components from untrusted or externally-authored IDL files.
🔒 Security
- #240 — Sanitize IDL text written into generated comments and strings (PSIRT-3497). A crafted IDL could break out of a generated
/* */,(* *),''', or CMake bracketed comment — including via Java\uXXXXunicode escapes and C/C++ backslash line-splicing — and inject arbitrary code into generated bindings. Fix adds both input validation and output sanitization, with unit tests.
✨ New features
- #225 — WebAssembly (WASM) bindings via emscripten. (@vijaiaeroastro)
- #220 — C++ binding/implementation thread-safety options (
none/soft/strict). (@Kimeek42) - #222 — Command-line flag to suppress
CMakeLists.txtgeneration. (@spywo)
🟩 Node.js bindings
- #239 — Support
basicarray/structarrayparameters and class inheritance (V8 API). Previously arrays were emitted as0, nullptrstubs. Compatibility fixes for newer V8 APIs (verified on Node 12+). (@YackerYan)
🐍 Python bindings
- #234 — Harden Python bindings against shutdown-time destructor errors.
- #230 — Add getter methods on the generated Python exception class.
- #229 — Fix Python bindings struct out-parameter handling.
- #228 — Fix Python out-parameter handling (also improves C# wrapper visibility).
- #227 — Loosen overly-restrictive regex validation for IDL descriptions.
#️⃣ C# bindings
- #231 — Generate a project-specific C# exception class.
- #228 — Improve C# wrapper visibility (bundled with Python fix above).
- #215 — C# crash fix: pass structs through bindings by ref.
☕ Java bindings
- #235 — Fix JNI prefix for
Function.
🅲 C++ bindings
- #232 — Use specific class type instead of
BaseClassNameinParameterCachetemplate generation. - #221 — Fix C++ include header being written in lowercase.
📚 Examples & documentation
- #223 — Fix existing examples and add documentation to the Primes example.
🔧 CI / build
- #224 — Update GitHub Actions Windows runner from 2019 to 2022.
- Pin emsdk to 4.0.21 in the example build image (bundled with #240; Python 3.10 unavailable on CentOS 8).
👋 New contributors
- @spywo — first PR: #221
- @gangatp — first PR: #215
- @Kimeek42 — first PR: #220
- @YackerYan — first PR: #239
Full changelog: v1.8.0-alpha...v1.8.1-alpha