4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether sharp is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
GHSA-f88m-g3jw-g9cj
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
UNKNOWN
GHSA-rgj7-g3m4-5g8c
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
HIGH 7.8
GHSA-54xq-cgqr-rpm3
sharp vulnerability in libwebp dependency CVE-2023-4863
MEDIUM 6.5
CVE-2022-29256
sharp vulnerable to Command Injection in post-installation over build environment
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes