{"id":"GHSA-wq5f-xc86-pv6w","title":"sharp : Vulnerability in librsvg dependency CVE-2026-96889","summary":"sharp : Vulnerability in librsvg dependency CVE-2026-96889","severity":"high","cwe":["CWE-416","CWE-1395"],"vendor":"sharp","product":"sharp","ecosystem":"npm","affected":["sharp < 0.35.5"],"patched":["sharp 0.35.5"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T13:43:58Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wq5f-xc86-pv6w","references":[{"url":"https://github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w"},{"url":"https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236"},{"url":"https://github.com/lovell/sharp/releases/tag/v0.35.5"},{"url":"https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-96889"},{"url":"https://github.com/advisories/GHSA-wq5f-xc86-pv6w"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-06T14:00:19.133Z","slug":"GHSA-wq5f-xc86-pv6w","body":"## Overview\n\n### Impact\n\nA memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.\n\n#### Using a globally-installed librsvg?\n\nPlease ensure you are using the latest librsvg 2.63.2.\n\n### Workarounds\n\nAdd the following to your code to prevent sharp from decoding SVG images.\n```js\nsharp.block({ operation: [\"VipsForeignLoadSvg\"] });\n```\n\nTo avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the \"official\" Node.js binaries do not.\n1\n\n## Affected packages\n\n- `sharp < 0.35.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `sharp 0.35.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}