GHSA-wq5f-xc86-pv6w
### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ### Patches #### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binaries provided by sharp. Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2. #### Using a globally-installed librsvg? Please ensure you are using the latest librsvg 2.63.2. ### Workarounds Add the following to your code to prevent sharp from decoding SVG images. ```js sharp.block({ operation: ["VipsForeignLoadSvg"] }); ``` To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1
Properties
- ghsa_id
- GHSA-wq5f-xc86-pv6w
- severity
- high
- summary
- sharp : Vulnerability in librsvg dependency CVE-2026-96889
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-wq5f-xc86-pv6w
- signal_observed_at
- 2026-10-06T14:27:41+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-06T14:27:41+00:00
- ghsa_published
- 2026-10-06T13:43:57Z
- source_url
- https://github.com/advisories/GHSA-wq5f-xc86-pv6w
- ghsa_updated
- 2026-10-06T13:43:58Z
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph