CVE-2026-56379
N/A 0ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
NO EXPLOITATION SIGNALS
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
1.2%chance of exploitation in 30 days · 64th percentile
○ In CISA KEV
○ Public exploit / PoC
Impact if exploited
0CVSS 4.0 · NONE
- ConfidentialityNone
- IntegrityNone
- AvailabilityNone
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
- ✓Requirements: No special attack requirements
✓ lowers the bar for an attacker · ⚠ raises it
Affected
Vendors Imagemagick Red Hat
Products Imagemagick Red Hat Enterprise Linux Server (V. 7 Els) Red Hat Enterprise Linux Server Optional (V. 7 Els) Red Hat Enterprise Linux 6
Weakness (CWE)
- CWE-116
- CWE-78: OS command injection
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N