{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105404", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-05T10:56:23.833Z", "datePublished": "2026-10-08T14:10:26.254Z", "dateUpdated": "2026-10-08T17:52:43.956Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T14:10:26.254Z" }, "datePublic": "2026-09-21T00:00:00.000Z", "title": "ImageMagick before 7.1.2-31 Code Injection via PostScript Coders", "descriptions": [ { "lang": "en", "value": "ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Improper Control of Generation of Code ('Code Injection')", "cweId": "CWE-94", "type": "CWE" } ] } ], "affected": [ { "vendor": "ImageMagick", "product": "ImageMagick", "defaultStatus": "unaffected", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "7.1.2-31" }, { "version": "7.1.2-31", "status": "unaffected", "versionType": "semver" } ] }, { "vendor": "ImageMagick", "product": "ImageMagick", "defaultStatus": "unaffected", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "6.9.13-56" }, { "version": "6.9.13-56", "status": "unaffected", "versionType": "semver" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*", "versionEndExcluding": "7.1.2-31" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*", "versionEndExcluding": "6.9.13-56" } ] } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "userInteraction": "PASSIVE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 6, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892", "tags": [ "vendor-advisory" ], "name": "GitHub Security Advisory (GHSA-5rg6-j44q-q892)" }, { "name": "VulnCheck Advisory: ImageMagick before 7.1.2-31 Code Injection via PostScript Coders", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-code-injection-via-postscript-coders" } ], "credits": [ { "lang": "en", "value": "t4kemyh4nd", "type": "reporter" }, { "lang": "en", "value": "rexpository", "type": "reporter" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T15:42:59.830337Z", "id": "CVE-2026-105404", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T17:52:43.956Z" } } ] } }