Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56379

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 8.1
CVSS3: 5.5
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия до 6.9.13-40 (исключая)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 7.1.0-0 (включая) до 7.1.2-15 (исключая)

EPSS

Процентиль: 58%
0.00884
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-116
CWE-78

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
redhat
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
debian
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection ...

suse-cvrf
около 1 месяца назад

Security update for GraphicsMagick

suse-cvrf
около 2 месяцев назад

Security update for GraphicsMagick

EPSS

Процентиль: 58%
0.00884
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-116
CWE-78