CRITICAL 9.8 npm
Astro: Remote code execution through AVIF image optimization
GHSA-26w7-cxv4-gfx2
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability in libheif, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.
Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.
The fix was released in Astro 7.2.8, which requires Sharp 0.35.4.
References
- WEB https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
- WEB https://github.com/withastro/astro/security/advisories/GHSA-26w7-cxv4-gfx2
- WEB https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b
- PACKAGE https://github.com/withastro/astro
- WEB https://github.com/withastro/astro/releases/tag/astro@7.2.8
Ready to move
Start Securing
Free, no credit card | First findings in minutes