Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56379

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

A flaw was found in ImageMagick. This command injection vulnerability in the SVG (Scalable Vector Graphics) decoder allows a remote attacker to craft malicious SVG files. When these files are processed, the injected Magick Vector Graphics (MVG) commands can execute, potentially leading to arbitrary code execution on the affected system.

Отчет

An Important-rated vulnerability in the default configuration of Mojolicious::Plugin::Web::Auth::OAuth2 allows remote attackers to hijack user sessions. Because the plugin defaults to generating predictable security tokens, an attacker can bypass protections and launch Cross-Site Request Forgery (CSRF) attacks against the application.

Меры по смягчению последствий

Restrict ImageMagick processing capabilities via policy.xml, disabling the SVG coder and restricting delegates to prevent injection escalation to OS command execution. Enforce mandatory access control (SELinux/AppArmor) combined with seccomp syscall filtering to block execve. For systemd services, enable NoNewPrivileges, ProtectSystem=strict, ProtectHome=true, and PrivateDevices=true.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportImageMagickFixedRHSA-2026:3296129.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2491700ImageMagick: ImageMagick: Arbitrary code execution via SVG decoder command injection

EPSS

Процентиль: 55%
0.00884
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
nvd
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection ...

suse-cvrf
4 дня назад

Security update for ImageMagick

suse-cvrf
4 дня назад

Security update for ImageMagick

EPSS

Процентиль: 55%
0.00884
Низкий

8.1 High

CVSS3