Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-56379: ImageMagick versions let malicious SVG execute commands
CVE-2026-56379 · published 3 months ago
Summary
Older ImageMagick releases (up to 7.1.2-15 and 6.9.13-40) can run unwanted drawing commands hidden in SVG files. An attacker could supply a crafted SVG that makes the software execute arbitrary actions when the image is processed. Update the listed Magick.NET packages to the latest versions or apply the vendor's patch to stop this behavior.
What to do
- Update magick.net-q16-openmp-x86 to version 14.10.3.
- Update dirk lemstra magick.net-q8-anycpu to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-anycpu to version 14.10.3.
- Update dirk lemstra magick.net-q16-anycpu to version 14.10.3.
- Update dirk lemstra magick.net-q8-x86 to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-openmp-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-openmp-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-openmp-x64 to version 14.10.3.
- Update dirk lemstra magick.net-q8-openmp-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-x64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-x86 to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-x86 to version 14.10.3.
- Update dirk lemstra magick.net-q8-arm64 to version 14.10.3.
- Update dirk lemstra magick.net-q8-openmp-x64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-x64 to version 14.10.3.
- Update dirk lemstra magick.net-q8-x64 to version 14.10.3.
- Update dirk lemstra magick.net-q16-hdri-openmp-x64 to version 14.10.3.
- Update debian imagemagick to version 8:7.1.2.15+dfsg1-1.
- Update debian imagemagick to version 8:6.9.11.60+dfsg-1.3+deb11u11.
- Update debian imagemagick to version 8:6.9.11.60+dfsg-1.6+deb12u8.
- Update debian imagemagick to version 8:7.1.1.43+dfsg1-1+deb13u8.
- Update imagemagick to version 7.1.2.30-r00071.
- Update rootio-imagemagick to version 7.1.2.30-r00071.
- Update canonical imagemagick to version 8:6.7.7.10-6ubuntu3.13+esm25.
- Update canonical imagemagick to version 8:6.8.9.9-7ubuntu5.16+esm24.
- Update canonical imagemagick to version 8:6.9.7.4+dfsg-16ubuntu6.15+esm16.
- Update canonical imagemagick to version 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14.
- Update canonical imagemagick to version 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| nuget | – | magick.net-q16-openmp-x86 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-anycpu |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-anycpu |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-anycpu |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-x86 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-openmp-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-openmp-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-openmp-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-openmp-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-x86 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-x86 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-arm64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-openmp-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q8-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| nuget | dirk lemstra | magick.net-q16-hdri-openmp-x64 |
< 14.10.3 Fix: upgrade to 14.10.3
|
| – | imagemagick | imagemagick |
< 6.9.13-40 >= 7.1.0-0, < 7.1.2-15 < 7.1.2-15 cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
| Debian:11 | debian | imagemagick |
< 8:6.9.11.60+dfsg-1.3+deb11u11 Fix: upgrade to 8:6.9.11.60+dfsg-1.3+deb11u11
|
| Debian:12 | debian | imagemagick |
< 8:6.9.11.60+dfsg-1.6+deb12u8 Fix: upgrade to 8:6.9.11.60+dfsg-1.6+deb12u8
|
| Debian:13 | debian | imagemagick |
< 8:7.1.1.43+dfsg1-1+deb13u8 Fix: upgrade to 8:7.1.1.43+dfsg1-1+deb13u8
|
| Debian:14 | debian | imagemagick |
< 8:7.1.2.15+dfsg1-1 Fix: upgrade to 8:7.1.2.15+dfsg1-1
|
| Ubuntu:Pro:14.04:LTS | canonical | imagemagick |
< 8:6.7.7.10-6ubuntu3.13+esm25 Fix: upgrade to 8:6.7.7.10-6ubuntu3.13+esm25
|
| Ubuntu:Pro:16.04:LTS | canonical | imagemagick |
< 8:6.8.9.9-7ubuntu5.16+esm24 Fix: upgrade to 8:6.8.9.9-7ubuntu5.16+esm24
|
| Ubuntu:Pro:18.04:LTS | canonical | imagemagick |
< 8:6.9.7.4+dfsg-16ubuntu6.15+esm16 Fix: upgrade to 8:6.9.7.4+dfsg-16ubuntu6.15+esm16
|
| Ubuntu:Pro:20.04:LTS | canonical | imagemagick |
< 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14 Fix: upgrade to 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14
|
| Ubuntu:Pro:22.04:LTS | canonical | imagemagick |
< 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14 Fix: upgrade to 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14
|
| Ubuntu:Pro:24.04:LTS | canonical | imagemagick | All versions |
| Ubuntu:25.10 | canonical | imagemagick | All versions |
| Root:Alpine:3.24 | – | imagemagick |
< 7.1.2.30-r00071 Fix: upgrade to 7.1.2.30-r00071
|
| Root:Alpine:3.24 | – | rootio-imagemagick |
< 7.1.2.30-r00071 Fix: upgrade to 7.1.2.30-r00071
|
Original advisory text
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious...
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf... Third Party Advisory
- https://github.com/ImageMagick/ImageMagick/commit/9db96365ecab5de69cdec81b935967...
- https://github.com/ImageMagick/ImageMagick/commit/f63c78b3828933f1cc7cf499390248...
- https://github.com/advisories/GHSA-xpg8-7m6m-jf56
- https://security-tracker.debian.org/tracker/CVE-2026-56379 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-56379 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-56379 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json URL
- https://access.redhat.com/errata/RHSA-2026:32961 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-56379 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56379... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56379 Vendor Advisory
- https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decod... Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491700 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8739-1 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 5.5 (NVD)
CVSS 4.0: 0.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-77Command Injection
CWE-116Improper Encoding or Escaping of Output
CWE-78OS Command Injection
Timeline
Published23 Jun 2026
Updated22 Sep 2026
First seen6 Mar 2026
Sources
GHSA-xpg8-7m6m-jf56 · GHSA
CVE-2026-56379 · OSV
DEBIAN-CVE-2026-56379 · OSV
UBUNTU-CVE-2026-56379 · OSV
CVE-2026-56379 · NVD
CVE-2026-56379 · MITRE
Track software like this
Free during beta