LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-56379

imagemagick · imagemagick

Published
CVSS8.1
Severityhigh
WeaknessCWE-116
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-56379

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-56379.