PT-2026-51514 · Unknown+1 · Imagemagick+1
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-15
ImageMagick versions prior to 6.9.13-40
Description
A command injection issue exists in the SVG decoder. This allows attackers to inject arbitrary Magick Vector Graphics (MVG) drawing commands by crafting malicious SVG files, which are then executed during the rendering process.
Recommendations
Update to version 7.1.2-15 or later.
Update to version 6.9.13-40 or later.
Exploit
Fix
DoS
OS Command Injection
Improper Encoding or Escaping of Output
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick
Red Os