---
id: CVE-2026-56379
title: >-
  ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection
  vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG
  drawing commands
summary: >-
  ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection
  vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG
  drawing commands. Attackers can craft malicious SVG files with injected Magick
  Vector G…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-116
  - CWE-78
  - CWE-77
vendor: imagemagick
product: imagemagick
affected:
  - imagemagick < 6.9.13-40
  - 'imagemagick >= 7.1.0-0, < 7.1.2-15'
patched:
  - imagemagick 7.1.2-15
published: '2026-06-23'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56379'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder
    label: disclosure@vulncheck.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:32961'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-56379'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491700'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://github.com/ImageMagick/ImageMagick/commit/9db96365ecab5de69cdec81b9359672b3a827aaa
  - url: >-
      https://github.com/ImageMagick/ImageMagick/commit/f63c78b3828933f1cc7cf499390248981af765aa
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56379'
  - url: 'https://github.com/advisories/GHSA-xpg8-7m6m-jf56'
tags:
  - nvd
  - ghsa
  - nuget
epss: 0.01643
epssPercentile: 0.75464
ingestedAt: '2026-07-03T13:02:27.822Z'
aliases:
  - GHSA-xpg8-7m6m-jf56
ecosystem: nuget
---

## Overview

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

## Affected

- `imagemagick < 6.9.13-40`
- `imagemagick >= 7.1.0-0, < 7.1.2-15`

## Remediation

Upgrade past the affected range:

- `imagemagick 7.1.2-15`

## Package advisory (CVE-2026-56379)

Affected packages:

- `Magick.NET-Q16-AnyCPU < 14.10.3`
- `Magick.NET-Q16-HDRI-AnyCPU < 14.10.3`
- `Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.10.3`
- `Magick.NET-Q16-HDRI-OpenMP-x64 < 14.10.3`
- `Magick.NET-Q16-HDRI-arm64 < 14.10.3`
- `Magick.NET-Q16-HDRI-x64 < 14.10.3`
- `Magick.NET-Q16-HDRI-x86 < 14.10.3`
- `Magick.NET-Q16-OpenMP-arm64 < 14.10.3`
- `Magick.NET-Q16-OpenMP-x64 < 14.10.3`
- `Magick.NET-Q16-OpenMP-x86 < 14.10.3`
- `Magick.NET-Q16-arm64 < 14.10.3`
- `Magick.NET-Q16-x64 < 14.10.3`
- `Magick.NET-Q16-x86 < 14.10.3`
- `Magick.NET-Q8-AnyCPU < 14.10.3`
- `Magick.NET-Q8-OpenMP-arm64 < 14.10.3`
- `Magick.NET-Q8-OpenMP-x64 < 14.10.3`
- `Magick.NET-Q8-arm64 < 14.10.3`
- `Magick.NET-Q8-x64 < 14.10.3`
- `Magick.NET-Q8-x86 < 14.10.3`

Patched in:

- `Magick.NET-Q16-AnyCPU 14.10.3`
- `Magick.NET-Q16-HDRI-AnyCPU 14.10.3`
- `Magick.NET-Q16-HDRI-OpenMP-arm64 14.10.3`
- `Magick.NET-Q16-HDRI-OpenMP-x64 14.10.3`
- `Magick.NET-Q16-HDRI-arm64 14.10.3`
- `Magick.NET-Q16-HDRI-x64 14.10.3`
- `Magick.NET-Q16-HDRI-x86 14.10.3`
- `Magick.NET-Q16-OpenMP-arm64 14.10.3`
- `Magick.NET-Q16-OpenMP-x64 14.10.3`
- `Magick.NET-Q16-OpenMP-x86 14.10.3`
- `Magick.NET-Q16-arm64 14.10.3`
- `Magick.NET-Q16-x64 14.10.3`
- `Magick.NET-Q16-x86 14.10.3`
- `Magick.NET-Q8-AnyCPU 14.10.3`
- `Magick.NET-Q8-OpenMP-arm64 14.10.3`
- `Magick.NET-Q8-OpenMP-x64 14.10.3`
- `Magick.NET-Q8-arm64 14.10.3`
- `Magick.NET-Q8-x64 14.10.3`
- `Magick.NET-Q8-x86 14.10.3`

Source: https://github.com/advisories/GHSA-xpg8-7m6m-jf56
