CVE-2026-56379
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
EPSS 0.90%
Description
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
How to fix CVE-2026-56379
To remediate CVE-2026-56379, upgrade the affected package to a fixed version below.
- Debian/imagemagick—upgrade to 8:6.9.11.60+dfsg-1.3+deb11u11 or later
Is CVE-2026-56379 being exploited?
Low — EPSS is 0.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8:6.9.11.60+dfsg-1.3+deb11u11
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |