๐Ÿ” CVE Alert

CVE-2026-106577

MEDIUM 5.3

ImageMagick: Code Injection in the postscript coders

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.

CWE CWE-94
Vendor imagemagick
Product imagemagick
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for imagemagick imagemagick

Be the first to know when new medium vulnerabilities affecting imagemagick imagemagick are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

ImageMagick / ImageMagick
< 6.9.13-56 >= 7.0.0, < 7.1.2-31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892 github.com: https://github.com/ImageMagick/ImageMagick/commit/2ba2edfd04a1ab3d45af4a0dc1e640dde7020192 github.com: https://github.com/ImageMagick/ImageMagick/commit/78378cd623468760bee82a5930cb3011725916f8 github.com: https://github.com/ImageMagick/ImageMagick6/commit/879489740daa44dd72e9405b26c845e8aa3d2f53 github.com: https://github.com/ImageMagick/ImageMagick6/commit/d5750d7309ef5a8cd561430d932a183e4168f484 github.com: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31 github.com: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56