criticalCVSS 9.8Vulnerability

GHSA-26w7-cxv4-gfx2

A vulnerability in `libheif`, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized. Projects are affected when an attacker can cause Astro to process an untrusted AVIF image. The fix was released in Astro 7.2.8, which requires Sharp 0.35.4.

Properties

ghsa_id
GHSA-26w7-cxv4-gfx2
severity
critical
summary
Astro: Remote code execution through AVIF image optimization
cvss_score
9.8
cve_id
GHSA-26w7-cxv4-gfx2
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-09-08T21:26:16Z
source_url
https://github.com/advisories/GHSA-26w7-cxv4-gfx2
ghsa_updated
2026-09-08T21:26:18Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/astro

AFFECTS (1)

[Software]npm/astro

HAS_WEAKNESS (2)

[Weakness]Out-of-bounds Read
[Weakness]Out-of-bounds Write

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-26w7-cxv4-gfx2 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal