{"id":"CVE-2026-108693","title":"ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered","summary":"ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered. Attackers can plant a malicious gswi…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-427"],"published":"2026-10-11","updated":"2026-10-11","sourceUpdated":"2026-10-11T02:16:37.607","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108693","references":[{"url":"https://github.com/ImageMagick/ImageMagick","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/blob/211e5b975a0019a88dcef5f84c1193f46738d815/MagickCore/nt-base.c#L1469-L1511","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/blob/211e5b975a0019a88dcef5f84c1193f46738d815/MagickCore/nt-base.c#L2829-L2832","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ghostx-86/exploitarium/tree/main/imagemagick-gs-delegate-hijack-poc","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-through-7.1.2-33-and-6.9.13-58-uncontrolled-search-path-via-ghostscript-delegate","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-11T02:38:44.034Z","slug":"CVE-2026-108693","body":"## Overview\n\nImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered. Attackers can plant a malicious gswin64c.exe in the working directory to execute code with ImageMagick privileges when PDF, PostScript, or EPS files are converted.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}