Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders.
Published: 2026-10-08
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Code Injection via PostScript coders enabling arbitrary PostScript execution
Action: Patch ASAP
AI Analysis

Impact

imageMagick versions before 6.9.13-56 and 7.x before 7.1.2-31 process PostScript files without properly escaping certain values that are written to the output. Attackers can craft input files that embed arbitrary PostScript code, which will be executed when the image is processed or re‑converted. This flaw is the instance of CWE-94, a code injection weakness that can lead to untrusted code execution in the context of the ImageMagick process.

Affected Systems

The vulnerability affects ImageMagick’s core product, specifically releases prior to 6.9.13-56 and all 7.x releases before 7.1.2-31. Systems running these versions, regardless of operating system, may be impacted if they handle PostScript input or generate PostScript output with ImageMagick.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, reflecting the potential for code injection but also suggesting that successful exploitation likely requires both the ability to supply crafted input and for the processed file to trigger execution of the injected code. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector involves an attacker supplying a malicious PostScript file to an application that uses ImageMagick to generate or re‑encode images. If the application runs ImageMagick with elevated privileges, the injected code may execute with those privileges.

Generated by OpenCVE AI on October 8, 2026 at 15:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2-31 or newer (or 6.9.13-56 or newer)
  • If upgrading is not immediately possible, disable or remove PostScript coders from the ImageMagick installation to prevent generation of PostScript output
  • Sanitize and escape any user‑supplied input before passing it to ImageMagick, ensuring that PostScript control characters cannot be injected

Generated by OpenCVE AI on October 8, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders.
Title ImageMagick before 7.1.2-31 Code Injection via PostScript Coders
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-94
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:52:43.956Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:33.800

Modified: 2026-10-08T15:17:33.800

Link: CVE-2026-105404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:45:11Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')