Command Injection Vulnerability in ImageMagick by ImageMagick
CVE-2026-56379

9.2CRITICAL

Key Information:

Vendor
CVE Published:
23 June 2026

What is CVE-2026-56379?

A command injection vulnerability exists in the SVG decoder of ImageMagick prior to version 7.1.2-15 and 6.9.13-40. This flaw allows an attacker to craft malicious SVG files that contain injected Magick Vector Graphics (MVG) commands. When these SVG files are rendered, the injected commands can be executed, potentially compromising the host system. This poses serious security risks as attackers can manipulate graphics rendering functions to execute arbitrary commands, leading to unauthorized access or data breaches.

Affected Version(s)

ImageMagick 0 < 7.1.2-15

ImageMagick 0 < 6.9.13-40

ImageMagick 7.1.2-15

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

phenggeler
.