lowVulnerability
GHSA-xpg8-7m6m-jf56
An attacker can inject arbitrary MVG (Magick Vector Graphics) drawing commands in an SVG file that is read by the internal SVG decoder of ImageMagick. The injected MVG commands execute during rendering.
Properties
- ghsa_id
- GHSA-xpg8-7m6m-jf56
- severity
- low
- summary
- ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
- cve_id
- GHSA-xpg8-7m6m-jf56
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-02-25T19:12:48Z
- source_url
- https://github.com/advisories/GHSA-xpg8-7m6m-jf56
- ghsa_updated
- 2026-02-25T19:12:49Z
Related Entities (22)
AFFECTS (19)
→[Software]nuget/Magick.NET-Q8-x86
→[Software]nuget/Magick.NET-Q8-AnyCPU
→[Software]nuget/Magick.NET-Q16-x64
→[Software]nuget/Magick.NET-Q16-OpenMP-x64
→[Software]nuget/Magick.NET-Q16-x86
→[Software]nuget/Magick.NET-Q16-HDRI-x64
→[Software]nuget/Magick.NET-Q8-OpenMP-x64
→[Software]nuget/Magick.NET-Q16-HDRI-x86
→[Software]nuget/Magick.NET-Q16-OpenMP-x86
→[Software]nuget/Magick.NET-Q16-AnyCPU
→[Software]nuget/Magick.NET-Q8-x64
→[Software]nuget/Magick.NET-Q16-HDRI-AnyCPU
→[Software]nuget/Magick.NET-Q8-OpenMP-arm64
→[Software]nuget/Magick.NET-Q8-arm64
→[Software]nuget/Magick.NET-Q16-HDRI-arm64
→[Software]nuget/Magick.NET-Q16-HDRI-OpenMP-arm64
→[Software]nuget/Magick.NET-Q16-arm64
→[Software]nuget/Magick.NET-Q16-OpenMP-arm64
→[Software]nuget/Magick.NET-Q16-HDRI-OpenMP-x64
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
→[Weakness]Improper Encoding or Escaping of Output
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph