Uncontrolled Search Path Vulnerability in ImageMagick on Windows
ImageMagick versions through 7.1.2-33 and 6.9.13-58 are vulnerable to arbitrary code execution via binary planting due to an insecure search path for gswin64c.exe.
CVE search metadata
CVE search record: CVE-2026-108693. Severity: high. CVSS: 7.0. KEV: no. Product: ImageMagick (<= 7.1.2-33, <= 6.9.13-58). Brief: Uncontrolled Search Path Vulnerability in ImageMagick on Windows. Brief link: https://feed.craftedsignal.io/briefs/2026-10-imagemagick-search-path/
ImageMagick on Windows, specifically versions through 7.1.2-33 and 6.9.13-58, contains an uncontrolled search path vulnerability within the NTGhostscriptEXE() function. When the Ghostscript utility is not explicitly registered in the system environment, ImageMagick attempts to locate and execute the 'gswin64c.exe' binary using its bare name. This behavior allows the application to search the current working directory before system-wide paths. An attacker with the ability to influence the working directory of the ImageMagick process - often by inducing a user to convert a malicious PDF, PostScript, or EPS file - can plant a rogue executable named 'gswin64c.exe'. When ImageMagick is triggered to process the file, it will execute the attacker-supplied binary with the privileges of the ImageMagick process, leading to arbitrary code execution.
Impact
Successful exploitation allows local arbitrary code execution with the permissions of the user running the ImageMagick utility. This vulnerability impacts all Windows deployments of ImageMagick within the specified version ranges that have not registered Ghostscript globally. If exploited, an attacker could achieve persistence, exfiltrate local data, or pivot within the host environment.
Recommendation
Prioritize patching ImageMagick to a version beyond 7.1.2-33 or 6.9.13-58 as soon as an official fix is provided by the vendor. In the interim, ensure Ghostscript is correctly registered in the system environment variables to prevent the application from defaulting to insecure local path lookups for 'gswin64c.exe'.
Mitigations
Register Ghostscript in the Windows system environment variables or update ImageMagick to a patched version once released.
CVE-2026-108693