CVE-2026-105404: ImageMagick before 7.1.2-31 Code Injection via PostScript Coders
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
ImageMagick versions before 6.9.13-56 and 7.x versions before 7.1.2-31 are affected. Exposure applies when PostScript coders generate output using values that an attacker can influence.
What must an attacker do to exploit this issue?
An attacker must supply crafted values that are written into output produced by ImageMagick's PostScript coders. The values can embed arbitrary PostScript code because they are not properly escaped or trimmed.
How can this be remediated?
Upgrade ImageMagick to 6.9.13-56 or later in the 6.x branch, or to 7.1.2-31 or later in the 7.x branch.