{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gimp-all-versions-prior-to-fix/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GIMP (all versions prior to fix)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["GIMP"],"content_html":"\u003cp\u003eA memory corruption vulnerability (CVE-2026-90947) has been identified in the GIMP image manipulation software. The flaw resides within the Lighting Effects filter, which fails to correctly validate the number of light sources defined within a GIMP lighting preset file. When a user opens a specially crafted preset file containing an unexpected number of light sources, the application performs an out-of-bounds write operation, leading to memory corruption. This vulnerability exposes users to potential application crashes or, in specific scenarios, arbitrary code execution in the context of the user running the application. This issue impacts GIMP across all supported platforms, including Windows, Linux, and macOS. Defenders should prioritize patching GIMP versions to the latest available release as identified by the project's security advisories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90947 could lead to full compromise of the user account running GIMP. This threat is particularly relevant in environments where users frequently import or share graphical design presets. If the application is running with elevated privileges, the impact of arbitrary code execution is significantly magnified. There is currently no report of large-scale exploitation in the wild, but the nature of the flaw makes it a viable candidate for targeted social engineering attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of GIMP to the latest version provided by the GIMP development team that addresses CVE-2026-90947.\u003c/li\u003e\n\u003cli\u003eImplement application allowlisting or restricted execution policies for image processing software to limit the impact of potential arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eEducate users regarding the risks of opening external preset files or image configuration files from untrusted sources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T17:34:53Z","date_published":"2026-09-14T17:34:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gimp-oob-write/","summary":"GIMP contains an out-of-bounds write vulnerability in its Lighting Effects filter, allowing potential arbitrary code execution when processing a maliciously crafted lighting preset file.","title":"Out-of-Bounds Write Vulnerability in GIMP Lighting Effects Filter (CVE-2026-90947)","url":"https://feed.craftedsignal.io/briefs/2026-09-gimp-oob-write/"}],"language":"en","title":"CraftedSignal Threat Feed - GIMP (All Versions Prior to Fix)","version":"https://jsonfeed.org/version/1.1"}