libsixel Security Overview (2018–2025) and Emergency Fix Plan #203
saitoha
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
📝 Preface
Over the past five years, while I (saitoha) have been absent, many contributors across the community have kept libsixel alive and evolving. In particular, the libsixel/libsixel fork has seen active maintenance, fixes, and improvements. I want to express my deep gratitude to everyone who has carried the project forward during this time.
This repository is now in the process of catching up and integrating those fixes and improvements. As part of that effort, we are also reviewing and addressing all reported CVEs listed below.
👉 Until every CVE in this list is resolved, the project is operating in a “hotfix / emergency mode”:
master
branch head,once all CVEs are closed out, a new release will be tagged asv1.8.7
.The tables below provide a complete overview of all security issues reported against libsixel (both runtime CVEs and development dependency alerts), their current status, and downstream impact.
🛡️ libsixel Security Overview (CVE + Dependabot)
All CVEs reported for libsixel (2018–2025, including stb_image leftovers)
316c086
)07ab235
) / L: 🟡 in progress1c58a6e
) / L: ✅ fixed (138b4ee
)d299d67
)dc96cdc
)1c58a6e
) / L: ✅ fixed (138b4ee
)98189b8
) / L: ✅ fixed (d299d67
)39c2de0
) / L: ✅ fixed (dc96cdc
)0b1e0b3
/ v1.8.5)9d0a7ff
/ v1.8.4)9d0a7ff
/ v1.8.4)7808a06
/ v1.8.3)0b1e0b3
/ v1.8.5)cb373ab
/ v1.8.4)f39d6da
)76b491d
)5543354
/ v1.8.5)598c8c8
/ v1.8.5)a18b378
/ v1.8.5)814f831
/ v1.8.5)6367d2f
/ v1.8.4)b9a4175
/ v1.8.5)e17c076
/ v1.8.3)614e761
/ v1.8.3)d6e34fc
/ v1.8.3)93812d6
/ v1.8.3)93812d6
/ v1.8.3)93812d6
/ v1.8.3)93812d6
/ v1.8.3)b418f35
/ v1.8.4)614e761
/ v1.8.3)614e761
/ v1.8.3)614e761
/ v1.8.3)1af6800
/ v1.8.3)1377517
/ v1.8.3)5f64fb1
/ v1.8.3)e903c93
,a53c872
/ v1.8.3)f94bc6f
,84ed0bc
/ v1.8.2)f94bc6f
,84ed0bc
/ v1.8.2)Build/Dev Dependencies (Dependabot alerts)
Notes
saitoha/libsixel
to the fork (libsixel/libsixel
) starting at 1.10.3-1.Beta Was this translation helpful? Give feedback.
All reactions