PT-2026-51514 · Unknown+1 · Imagemagick+1

·

CVE-2026-56379

·

Published

2026-02-25

·

Updated

2026-09-08

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-15 ImageMagick versions prior to 6.9.13-40
Description A command injection issue exists in the SVG decoder. This allows attackers to inject arbitrary Magick Vector Graphics (MVG) drawing commands by crafting malicious SVG files, which are then executed during the rendering process.
Recommendations Update to version 7.1.2-15 or later. Update to version 6.9.13-40 or later.

Exploit

Fix

DoS

OS Command Injection

Improper Encoding or Escaping of Output

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09990
CVE-2026-56379
ECHO-25F8-9743-35BB
GHSA-XPG8-7M6M-JF56
JLSEC-2026-1060
OPENSUSE-SU-2026:11127-1
OPENSUSE-SU-2026:11414-1
OPENSUSE-SU-2026:21291-1
OPENSUSE-SU-2026:21426-1
OPENSUSE-SU-2026:21553-1
SUSE-SU-2026:22620-1
SUSE-SU-2026:22861-1
SUSE-SU-2026:2877-1
SUSE-SU-2026:3023-1
SUSE-SU-2026:3024-1
SUSE-SU-2026:3053-1
SUSE-SU-2026:3219-1
SUSE-SU-2026:3298-1
SUSE-SU-2026:3335-1
SUSE-SU-2026:3336-1
SUSE-SU-2026:3441-1
USN-8739-1

Affected Products

Imagemagick
Red Os