code16/sharp Security Advisories for v9.21.1 (4)
-
[HIGH] code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
PKSA-735v-pwws-tf2j CVE-2026-61823 GHSA-qxg3-46rw-79j8
Affected version: <9.22.5
Reported by:
GitHub -
[HIGH] code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
PKSA-p6zx-3z97-z7f8 CVE-2026-61825 GHSA-vj3q-vp3g-j9c8
Affected version: <9.22.5
Reported by:
GitHub -
[MEDIUM] Sharp Missing Authorization Check in Quick Creation Command Endpoints
PKSA-krdf-j5zz-ky6v CVE-2026-53634 GHSA-vmwx-m75v-qvch
Affected version: >=9.0.0,<9.22.3
Reported by:
GitHub -
[HIGH] Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint
PKSA-h9kt-ss6k-xq4z CVE-2026-44692 GHSA-748w-hm6r-qc7v
Affected version: <9.22.0
Reported by:
GitHub