GHSA-26w7-cxv4-gfx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-26w7-cxv4-gfx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-26w7-cxv4-gfx2/GHSA-26w7-cxv4-gfx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-26w7-cxv4-gfx2
Published
2026-09-08T21:26:16Z
Modified
2026-09-08T21:30:05Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Astro: Remote code execution through AVIF image optimization
Details

A vulnerability in libheif, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.

Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.

The fix was released in Astro 7.2.8, which requires Sharp 0.35.4.

Database specific
{
    "cwe_ids": [
        "CWE-125",
        "CWE-787"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-08T21:26:16Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / astro

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.2.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-26w7-cxv4-gfx2/GHSA-26w7-cxv4-gfx2.json"