CVE-2026-56379

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

02 Jul 2026, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 0.0
v2 : unknown
v3 : 8.1

30 Jun 2026, 03:21

Type Values Removed Values Added
CWE CWE-78
References
  • () https://access.redhat.com/errata/RHSA-2026:32961 -
  • () https://access.redhat.com/security/cve/CVE-2026-56379 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2491700 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json -

24 Jun 2026, 14:37

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
First Time Imagemagick
Imagemagick imagemagick
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56 - Third Party Advisory
References () https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder - () https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder - Third Party Advisory

23 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 13:16

Updated : 2026-07-15 01:16


NVD link : CVE-2026-56379

Mitre link : CVE-2026-56379

CVE.ORG link : CVE-2026-56379


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-116

Improper Encoding or Escaping of Output

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')