THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-26w7-cxv4-gfx2 (critical) — Astro: Remote code execution through AVIF image optimization

[GHSA] GHSA-26w7-cxv4-gfx2 (critical) — Astro: Remote code execution through AVIF image optimization

medgithub_advisoriesPublished 2026-09-08

GHSA-26w7-cxv4-gfx2 Severity: critical CVE: None

Astro: Remote code execution through AVIF image optimization

A vulnerability in `libheif`, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.

Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.

The fix was released in Astro 7.2.8, wh

Original source: https://github.com/advisories/GHSA-26w7-cxv4-gfx2