Security researcher uses MiniMax M3 to build PoC for CVSS 8.8 bug in sharp's dependency chain

xeophon · x · 2026-10-04

Security researcher @xeophon reports his first CVE: a CVSS 8.8 memory corruption bug in Ghost. The trail started with last week's HEIF Heist vulnerability in libheif, which is bundled into libvips, which in turn is bundled into sharp, a widely used Node.js image processing library. Patches exist, but users must update their dependencies to be protected.

To reproduce the issue, he had MiniMax M3 build a working PoC image file and script, demonstrating a concrete LLM-assisted security research workflow — and a reminder for Node ecosystem users to update the sharp dependency chain.

Original post →

More from Safety

Safety channel →