---
id: CVE-2026-105404
title: >-
  ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection
  vulnerability in its PostScript coders, because some values are not properly
  escaped or trimmed when written to output
summary: >-
  ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection
  vulnerability in its PostScript coders, because some values are not properly
  escaped or trimmed when written to output. Attackers can supply crafted values
  th…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-94
vendor: ImageMagick
product: ImageMagick
affected:
  - ImageMagick < 7.1.2-31
  - ImageMagick < 6.9.13-56
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:50:49.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105404'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-code-injection-via-postscript-coders
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T15:42:59.830337Z'
ingestedAt: '2026-10-08T14:47:16.363Z'
---

## Overview

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
