highVulnerability

GHSA-wq5f-xc86-pv6w

### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ### Patches #### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binaries provided by sharp. Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2. #### Using a globally-installed librsvg? Please ensure you are using the latest librsvg 2.63.2. ### Workarounds Add the following to your code to prevent sharp from decoding SVG images. ```js sharp.block({ operation: ["VipsForeignLoadSvg"] }); ``` To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1

Properties

ghsa_id
GHSA-wq5f-xc86-pv6w
severity
high
summary
sharp : Vulnerability in librsvg dependency CVE-2026-96889
last_source
GitHub Advisory Database
cve_id
GHSA-wq5f-xc86-pv6w
signal_observed_at
2026-10-06T14:27:41+00:00
is_ghsa_only
true
retrieved_at
2026-10-06T14:27:41+00:00
ghsa_published
2026-10-06T13:43:57Z
source_url
https://github.com/advisories/GHSA-wq5f-xc86-pv6w
ghsa_updated
2026-10-06T13:43:58Z

Related Entities (5)

VULNERABLE_TO (1)

←[Software]npm/sharp

AFFECTS (1)

→[Software]npm/sharp

HAS_WEAKNESS (2)

→[Weakness]Dependency on Vulnerable Third-Party Component
→[Weakness]Use After Free

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-wq5f-xc86-pv6w — Ninja Signal Threat Intelligence | Ninja Signal