{"id":"GHSA-26w7-cxv4-gfx2","summary":"Astro: Remote code execution through AVIF image optimization","details":"A vulnerability in `libheif`, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.\n\nProjects are affected when an attacker can cause Astro to process an untrusted AVIF image.\n\nThe fix was released in Astro 7.2.8, which requires Sharp 0.35.4.","modified":"2026-09-08T21:30:05.563003658Z","published":"2026-09-08T21:26:16Z","database_specific":{"cwe_ids":["CWE-125","CWE-787"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-09-08T21:26:16Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497"},{"type":"WEB","url":"https://github.com/withastro/astro/security/advisories/GHSA-26w7-cxv4-gfx2"},{"type":"WEB","url":"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b"},{"type":"PACKAGE","url":"https://github.com/withastro/astro"},{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/astro@7.2.8"}],"affected":[{"package":{"name":"astro","ecosystem":"npm","purl":"pkg:npm/astro"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-26w7-cxv4-gfx2/GHSA-26w7-cxv4-gfx2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}