Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. astro
  4. ›
  5. GHSA-26w7-cxv4-gfx2

GHSA-26w7-cxv4-gfx2: Astro: Remote code execution through AVIF image optimization

September 8, 2026

A vulnerability in libheif, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.

Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.

The fix was released in Astro 7.2.8, which requires Sharp 0.35.4.

References

  • github.com/advisories/GHSA-26w7-cxv4-gfx2
  • github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
  • github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b
  • github.com/withastro/astro/releases/tag/astro@7.2.8
  • github.com/withastro/astro/security/advisories/GHSA-26w7-cxv4-gfx2

Code Behaviors & Features

Detect and mitigate GHSA-26w7-cxv4-gfx2 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 7.2.8

Fixed versions

  • 7.2.8

Solution

Upgrade to version 7.2.8 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-125: Out-of-bounds Read
  • CWE-787: Out-of-bounds Write

Source file

npm/astro/GHSA-26w7-cxv4-gfx2.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:21:59 +0000.