CVE-2026-56379: ImageMagick
High severity, CVSS 8.1. EPSS: 1.6% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
Affected products
- ImageMagick ImageMagick: before 6.9.13-40 (fixed in 6.9.13-40); from 7.1.0-0, before 7.1.2-15 (fixed in 7.1.2-15)
Published 2026-06-23. Last modified 2026-07-15.