CVE-2026-106577

EUVD-2026-94397
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.84%
Debian logo
Debian Releases
Debian Product
Codename
imagemagick
bookworm
vulnerable
bookworm (security)
vulnerable
forky
8:7.1.2.31+dfsg1-1
fixed
sid
8:7.1.2.31+dfsg1-1
fixed
trixie
vulnerable
trixie (security)
vulnerable