Executive brief
ImageMagick is a widely-used image manipulation library that processes various file formats including SVG files. A vulnerability in its SVG decoder allows attackers to inject malicious drawing commands that execute during image rendering, potentially leading to code execution or service disruption when processing untrusted SVG files.
Technical details
This is an OS command injection vulnerability (CWE-78, CWE-116) in ImageMagick's SVG-to-MVG decoder (coders/svg.c). An attacker can craft a malicious SVG file containing injected Magick Vector Graphics (MVG) drawing commands that are executed during rendering without proper input validation or output encoding. The vulnerability is network-accessible and requires no authentication or user interaction beyond opening a malicious SVG file. ImageMagick versions before 7.1.2-15 (version 7.x) and 6.9.13-40 (version 6.x) are affected. Patches are available in the fixed versions.
Affected products
- ImageMagick ImageMagick < 7.1.2-15 and < 6.9.13-40
- dlemstra Magick.NET-Q16-AnyCPU < 14.10.3
Timeline
- 2026-02-23: disclosed: Vulnerability disclosed via GHSA-xpg8-7m6m-jf56
- 2026-06-23: advisory: Duplicate advisory GHSA-v772-658q-978p published
- 2026-02-23: patched: Patches available in ImageMagick 7.1.2-15 and 6.9.13-40; Magick.NET-Q16-AnyCPU 14.10.3