StackRadar

CVE-2022-29256

Medium

Advisory

Published 1 Jun 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

sharp vulnerable to Command Injection in post-installation over build environment

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
sharpnpm0.27.2, 0.28.1, 0.29.0, 0.29.2+2 more0.30.58
OSV records
GHSA-gp95-ppv5-3jc5

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
sharp@0.30.3
0.30.5

Open the chart page →

5,251
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sharp@0.29.0
0.30.5

Open the chart page →

24,488
dltbrokerassist-iot-distributed-broker0.2.01 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
sharp@0.27.2
0.30.5

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.01 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
sharp@0.27.2
0.30.5

Open the chart page →

77,687
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
sharp@0.29.3
0.30.5

Open the chart page →

4,260
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
sharp@0.29.3
0.30.5

Open the chart page →

13,738
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
sharp@0.27.2
0.30.5

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.1.0c8a170683be7
sharp@0.27.2
0.30.5

Open the chart page →

77,706
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
sharp@0.29.2
0.30.5

Open the chart page →

12,222
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-29256.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sharp@0.28.1
0.30.5

Open the chart page →

9,968

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
sharp@0.27.2
0.30.5
3
assistiot/dlt_api:2.1.0c8a170683be7
sharp@0.27.2
0.30.5
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sharp@0.29.0
0.30.5
1
jakowenko/double-take:1.6.0b858bac9e32a
sharp@0.29.2
0.30.5
1
library/ghost:4.37.0767230c0f263
sharp@0.29.3
0.30.5
1
misskey/misskey:12.110.1e08b7c478093
sharp@0.30.3
0.30.5
1
moreillon/food-manager:lateste8fd856e593d
sharp@0.29.3
0.30.5
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sharp@0.28.1
0.30.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.