THREAT OPS › Threat News › [GHSA] GHSA-26w7-cxv4-gfx2 (critical) — Astro: Remote code execution through AVIF image optimization
[GHSA] GHSA-26w7-cxv4-gfx2 (critical) — Astro: Remote code execution through AVIF image optimization
GHSA-26w7-cxv4-gfx2 Severity: critical CVE: None
Astro: Remote code execution through AVIF image optimization
A vulnerability in `libheif`, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.
Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.
The fix was released in Astro 7.2.8, wh
Original source: https://github.com/advisories/GHSA-26w7-cxv4-gfx2