{"id":"GHSA-wq5f-xc86-pv6w","summary":"sharp : Vulnerability in librsvg dependency CVE-2026-96889","details":"### Impact\n\nA memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.\n\n#### Using a globally-installed librsvg?\n\nPlease ensure you are using the latest librsvg 2.63.2.\n\n### Workarounds\n\nAdd the following to your code to prevent sharp from decoding SVG images.\n```js\nsharp.block({ operation: [\"VipsForeignLoadSvg\"] });\n```\n\nTo avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the \"official\" Node.js binaries do not.\n1","modified":"2026-10-06T14:00:04.195403132Z","published":"2026-10-06T13:43:57Z","database_specific":{"cwe_ids":["CWE-1395","CWE-416"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-06T13:43:57Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w"},{"type":"WEB","url":"https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236"},{"type":"PACKAGE","url":"https://github.com/lovell/sharp"},{"type":"WEB","url":"https://github.com/lovell/sharp/releases/tag/v0.35.5"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-96889"}],"affected":[{"package":{"name":"sharp","ecosystem":"npm","purl":"pkg:npm/sharp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.35.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wq5f-xc86-pv6w/GHSA-wq5f-xc86-pv6w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}