OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54627

CRITICAL · CVSS 9.8 EPSS 0.78% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the SAIL library, specifically in the handling of PSD files where a mismatch in pixel format depth can lead to memory corruption. Attackers can exploit this flaw to cause application crashes or potentially execute arbitrary code by loading specially crafted PSD files. Organizations using versions 0.9.10 and earlier of the SAIL library should prioritize upgrading to version 1.0.0 to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54627
Severity
CRITICAL
CVSS
9.8
EPSS
0.78%

Original NVD Description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v8_psd() in src/sail-codecs/psd/psd.c accepts depth == 8 and writes one attacker-controlled byte per pixel. Loading a crafted PSD through sail_load_from_file() or sail_load_from_memory() therefore writes beyond each heap row, causing memory corruption, a reliable crash, or potential code execution. This mode/depth mismatch is distinct from GHSA-rcqx-gc76-r9mv and GHSA-wcj8-hxxf-pq2c. This issue is fixed in version 1.0.0.