Unknown · Imagemagick · CVE-2026-56379
**Name of the Vulnerable Software and Affected Versions**
ImageMagick versions prior to 7.1.2-15
ImageMagick versions prior to 6.9.13-40
**Description**
A command injection issue exists in the SVG decoder. This allows attackers to inject arbitrary Magick Vector Graphics (MVG) drawing commands by crafting malicious SVG files, which are then executed during the rendering process.
**Recommendations**
Update to version 7.1.2-15 or later.
Update to version 6.9.13-40 or later.