GHSA-748w-hm6r-qc7v
HIGHCVE-2026-44692Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters.
- Affected
- < 9.22.0
- Fixed in
- 9.22.0
- Weakness
- CWE-639
- Published
- 2026-05-15
- Source
- github