CVE-2026-56379High· 8.1▾ TwilightImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
imagemagick < 6.9.13-40imagemagick >= 7.1.0-0, < 7.1.2-15Upgrade past the affected range:
imagemagick 7.1.2-15Affected packages:
Magick.NET-Q16-AnyCPU < 14.10.3Magick.NET-Q16-HDRI-AnyCPU < 14.10.3Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.10.3Magick.NET-Q16-HDRI-OpenMP-x64 < 14.10.3Magick.NET-Q16-HDRI-arm64 < 14.10.3Magick.NET-Q16-HDRI-x64 < 14.10.3Magick.NET-Q16-HDRI-x86 < 14.10.3Magick.NET-Q16-OpenMP-arm64 < 14.10.3Magick.NET-Q16-OpenMP-x64 < 14.10.3Magick.NET-Q16-OpenMP-x86 < 14.10.3Magick.NET-Q16-arm64 < 14.10.3Magick.NET-Q16-x64 < 14.10.3Magick.NET-Q16-x86 < 14.10.3Magick.NET-Q8-AnyCPU < 14.10.3Magick.NET-Q8-OpenMP-arm64 < 14.10.3Magick.NET-Q8-OpenMP-x64 < 14.10.3Magick.NET-Q8-arm64 < 14.10.3Magick.NET-Q8-x64 < 14.10.3Magick.NET-Q8-x86 < 14.10.3Patched in:
Magick.NET-Q16-AnyCPU 14.10.3Magick.NET-Q16-HDRI-AnyCPU 14.10.3Magick.NET-Q16-HDRI-OpenMP-arm64 14.10.3Magick.NET-Q16-HDRI-OpenMP-x64 14.10.3Magick.NET-Q16-HDRI-arm64 14.10.3Magick.NET-Q16-HDRI-x64 14.10.3Magick.NET-Q16-HDRI-x86 14.10.3Magick.NET-Q16-OpenMP-arm64 14.10.3Magick.NET-Q16-OpenMP-x64 14.10.3Magick.NET-Q16-OpenMP-x86 14.10.3Magick.NET-Q16-arm64 14.10.3Magick.NET-Q16-x64 14.10.3Magick.NET-Q16-x86 14.10.3Magick.NET-Q8-AnyCPU 14.10.3Magick.NET-Q8-OpenMP-arm64 14.10.3Magick.NET-Q8-OpenMP-x64 14.10.3Magick.NET-Q8-arm64 14.10.3Magick.NET-Q8-x64 14.10.3Magick.NET-Q8-x86 14.10.3Connected by shared product, vendor, weakness, or advisory.
GHSA-v772-658q-978pLowDuplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2026-56371Medium· 5.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…
CVE-2026-93586Low· 2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly
CVE-2026-93588Low· 3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder
CVE-2026-93587Low· 3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…