« List of all CVEs

CVE-2026-56379

ImageMagick - Command Injection via SVG Decoder

Published: 6/23/2026 Last updated: 7/15/2026 Reserved: 6/21/2026

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CNA assigner: VulnCheck (83251b91-4cc7-4094-a5c7-464a1b83ea10) Requested by: n/a

Metrics

Version Score Severity Vector String
4.0 9.2 Critical CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
3.1 8.1 High CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (2)

conf-libMagickCore ocsigen-start

Products affected (4)

Product Vendor Version
ImageMagick ImageMagick djvulibre-3.5.28 and earlier
ImageMagick ImageMagick n/a
ImageMagick ImageMagick 10 Version 1709 for ARM64-based Systems
ImageMagick ImageMagick 10 for 32-bit Systems

References (12)

Credits (2)