Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56379

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 8.1
CVSS3: 5.5
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия до 6.9.13-40 (исключая)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 7.1.0-0 (включая) до 7.1.2-15 (исключая)

EPSS

Процентиль: 56%
0.00884
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-116
CWE-78

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
redhat
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection ...

redos
около 1 месяца назад

Уязвимость ImageMagick7

redos
около 1 месяца назад

Уязвимость ImageMagick

EPSS

Процентиль: 56%
0.00884
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-116
CWE-78