CVE-2026-96889: Remote Code Execution via Use-After-Free in librsvg (VectorFreed)
Vulnerability ID: GHSA-WQ5F-XC86-PV6W
CVSS Score: 7.8
Published: 2026-10-06
VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.
TL;DR
A Use-After-Free vulnerability in librsvg (CVE-2026-96889) allows remote code execution when processing crafted SVG files with nested XML Inclusions (XInclude) and duplicate entity declarations, transitively impacting sharp, Next.js, and Ghost.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-416
- Attack Vector: Local / Network via Transitive Library Calls
- CVSS Base Score: 7.8 (High)
- EPSS Score: 0.00129 (Percentile: 2.15%)
- Exploit Status: Proof-of-Concept Available
- CISA KEV Status: Not Listed
Affected Systems
- librsvg
- sharp (npm package)
- Next.js (ImageResponse Node.js runtime path)
- Ghost (Bookmark Cards processing)
- Satori
-
librsvg: < 2.63.2 (Fixed in:
2.63.2) -
sharp: < 0.35.5 (Fixed in:
0.35.5) -
Next.js: >= 16.2.0, <= 16.3.5 (Fixed in:
16.3.6) -
Ghost: >= 6.56.0, < 6.67.0 (Fixed in:
6.67.0)
Code Analysis
Commit: 8a1b0cd
Fix entity redefinition handling during nested parsing contexts to prevent Use-After-Free.
Commit: 96de105
Upgrade bundled libvips dependencies to incorporate patched librsvg binaries.
Exploit Details
- GitHub: VectorFreed repository containing proof-of-concept scripts and dynamic detection details.
- GitHub Raw: Python utility script to generate various formats of the UAF exploit payload.
Mitigation Strategies
- Disable SVG loading operation inside sharp if vector graphics processing is not required.
- Apply security updates to downstream web frameworks (Next.js, Ghost) that handle server-side image generation.
- Deploy host-level binary protections including ASLR and PIE to hinder heap exploitation techniques.
Remediation Steps:
- Identify all instances of the sharp library in package.json files.
- Run 'npm install sharp@0.35.5' or update the dependency range to ensure sharp-libvips version 1.3.4 is pulled.
- For system-wide installations of librsvg on Linux, update the system packages using 'apt-get install librsvg2-dev' or 'yum update librsvg2'.
- Verify the installed version of librsvg is 2.63.2 or one of the backported versions (2.62.4, 2.61.5, 2.60.3).
References
- GitHub Advisory: Use-After-Free in sharp bundled dependency
- RustSec Security Advisory: Memory corruption in librsvg
- CVE Record: CVE-2026-96889
- Vercel Next.js Downstream Security Advisory
- Ghost Downstream Security Advisory
- Satori HTML/XML Escaping Bypass Advisory
Read the full report for GHSA-WQ5F-XC86-PV6W on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)