5.3

CVE-2026-106577

ImageMagick: Code Injection in the postscript coders

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt ImageMagick
Version < 6.9.13-56
Status affected
Version >= 7.0.0, < 7.1.2-31
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892
https://github.com/ImageMagick/ImageMagick/commit/2ba2edfd04a1ab3d45af4a0dc1e640dde7020192
https://github.com/ImageMagick/ImageMagick/commit/78378cd623468760bee82a5930cb3011725916f8
https://github.com/ImageMagick/ImageMagick6/commit/879489740daa44dd72e9405b26c845e8aa3d2f53
https://github.com/ImageMagick/ImageMagick6/commit/d5750d7309ef5a8cd561430d932a183e4168f484