GHSA-v772-658q-978pLow▾ SunlitDuplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-xpg8-7m6m-jf56. This link is maintained to preserve external references.
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
Magick.NET-Q16-AnyCPU < 14.10.3Upgrade to a patched release:
Magick.NET-Q16-AnyCPU 14.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56379High· 8.1ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands
GHSA-hc76-7mpc-qjqhMedium· 5.7ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
GHSA-8g9f-ccmr-vfvgMedium· 3.7Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-98gv-6gmj-cm6mLowDuplicate Advisory: ImageMagick: Memory leak in coders/txt.c without freetype
CVE-2026-56376Low· 3.7ImageMagick has a possible heap Use After Free vulnerability in its meta coder