OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

sharp : Vulnerability in librsvg dependency CVE-2026-96889

GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100

### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ### Patches #### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binaries provided by sharp. Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2. #### Using a globally-installed librsvg? Please ensure you are using the latest librsvg 2.63.2. ### Workarounds Add the following to your code to prevent sharp from decoding SVG images. ```js sharp.block({ operation: ["VipsForeignLoadSvg"] }); ``` To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1

Upgrade affected packages to a patched version: sharp 0.35.5.

Vendor
Not specified
Product
sharp
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source