sharp : Vulnerability in librsvg dependency CVE-2026-96889
### Impact A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux. ### Patches #### Using prebuilt binaries provided by sharp? Most people rely on the prebuilt binaries provided by sharp. Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2. #### Using a globally-installed librsvg? Please ensure you are using the latest librsvg 2.63.2. ### Workarounds Add the following to your code to prevent sharp from decoding SVG images. ```js sharp.block({ operation: ["VipsForeignLoadSvg"] }); ``` To avoid RCE, ensure you are using a `node` executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1
Recommended action
Recommended action
Upgrade affected packages to a patched version: sharp 0.35.5.
Technical details
- Vendor
- Not specified
- Product
- sharp
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source