Headline
GHSA-4vjr-crvh-383h: @napi-rs/image affected by libwebp CVE
Impact
Heap buffer overflow in libwebp
allows a remote attacker to perform an out of bounds memory write via a crafted webp image.
References
- https://github.com/advisories/GHSA-j7hp-h8jx-5ppr
- https://blog.isosceles.com/the-webp-0day/
@napi-rs/image affected by libwebp CVE
High severity GitHub Reviewed Published Sep 27, 2023 in Brooooooklyn/Image • Updated Sep 27, 2023