GHSA-wq5f-xc86-pv6wHigh▾ Twilightsharp : Vulnerability in librsvg dependency CVE-2026-96889
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.
Please ensure you are using the latest librsvg 2.63.2.
Add the following to your code to prevent sharp from decoding SVG images.
sharp.block({ operation: ["VipsForeignLoadSvg"] });
To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not.
1
sharp < 0.35.5Upgrade to a patched release:
sharp 0.35.5Connected by shared product, vendor, weakness, or advisory.
GHSA-f88m-g3jw-g9cjHighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-rgj7-g3m4-5g8cHighsharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
CVE-2026-61825High· 8.7code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces
CVE-2026-61823High· 7.3code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces
CVE-2025-20802Medium· 6.7In geniezone, there is a possible memory corruption due to use after free
CVE-2025-14372Medium· 6.1Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page