Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-1060 Critical 9.2

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG...

JLSEC Published
Modified
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Packages
ImageMagick_jll < 7.1.2023+0

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

References