---
id: GHSA-wq5f-xc86-pv6w
title: 'sharp : Vulnerability in librsvg dependency CVE-2026-96889'
summary: 'sharp : Vulnerability in librsvg dependency CVE-2026-96889'
severity: high
cwe:
  - CWE-416
  - CWE-1395
vendor: sharp
product: sharp
ecosystem: npm
affected:
  - sharp < 0.35.5
patched:
  - sharp 0.35.5
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T13:43:58Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wq5f-xc86-pv6w'
references:
  - url: 'https://github.com/lovell/sharp/security/advisories/GHSA-wq5f-xc86-pv6w'
  - url: >-
      https://github.com/lovell/sharp/commit/96de105d9d36ab04c76c2b78b97255171630d236
  - url: 'https://github.com/lovell/sharp/releases/tag/v0.35.5'
  - url: 'https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-96889'
  - url: 'https://github.com/advisories/GHSA-wq5f-xc86-pv6w'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-06T14:00:19.133Z'
---

## Overview

### Impact

A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.

### Patches

#### Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.

#### Using a globally-installed librsvg?

Please ensure you are using the latest librsvg 2.63.2.

### Workarounds

Add the following to your code to prevent sharp from decoding SVG images.
```js
sharp.block({ operation: ["VipsForeignLoadSvg"] });
```

To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not.
1

## Affected packages

- `sharp < 0.35.5`

## Remediation

Upgrade to a patched release:

- `sharp 0.35.5`
