Integer Overflow in GIMP Allows Remote Code Execution for Users
CVE-2026-4154

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
11 April 2026

What is CVE-2026-4154?

The vulnerability present in GIMP's handling of XPM file parsing exposes installations to potential exploitation by remote attackers. This occurs due to improper validation of user-supplied data, leading to an integer overflow before the allocation of a buffer. To successfully exploit this flaw, an attacker would need to persuade a victim to either visit a malicious webpage or open a specially crafted file, allowing the execution of arbitrary code within the context of the current process. Timely updates and awareness of this vulnerability are essential for users to safeguard their systems.

Affected Version(s)

GIMP 3.0.8

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.