GHSA-wq5f-xc86-pv6w

Suggest an improvement
Source
https://github.com/advisories/GHSA-wq5f-xc86-pv6w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wq5f-xc86-pv6w/GHSA-wq5f-xc86-pv6w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-wq5f-xc86-pv6w
Published
2026-10-06T13:43:57Z
Modified
2026-10-06T14:00:04Z
Severity
  • 8.9 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
sharp : Vulnerability in librsvg dependency CVE-2026-96889
Details

Impact

A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.

Patches

Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.

Using a globally-installed librsvg?

Please ensure you are using the latest librsvg 2.63.2.

Workarounds

Add the following to your code to prevent sharp from decoding SVG images.

sharp.block({ operation: ["VipsForeignLoadSvg"] });

To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1

Database specific
{
    "cwe_ids":  [
        "CWE-1395",
        "CWE-416"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-06T13:43:57Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / sharp

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.35.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wq5f-xc86-pv6w/GHSA-wq5f-xc86-pv6w.json"