The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Checked against the NVD CVE API (CVE-2026-108693, status Received, only VulnCheck CNA metrics: CVSS 3.1 7.0 AV:L/AC:H/PR:N/UI:R, CVSS 4.0 7.3; no NVD score), the CVE.org record (VulnCheck, published 2026-10-11, affected 7.0.0-0..7.1.2-33 and <=6.9.13-58, CWE-427) and GitHub advisory GHSA-92c8-5jfq-j2vj (unreviewed, high). 7.1.2-33 is the latest release; no fixed version named. No active exploitation reported; public PoC referenced.

Sourcing
1source

via NVD

NVD · track record
54Stories
100%Verified
3030d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/ImageMagick on Windows hit by high-severity Ghostscript path flaw
VERIFIEDBy Xavier Rivera· ·1 min read

ImageMagick on Windows hit by high-severity Ghostscript path flaw

CVE-2026-108693 lets an attacker run code on Windows by planting a fake gswin64c.exe that ImageMagick launches by bare name when Ghostscript is unregistered. VulnCheck, the CNA, rates it 7.0 (CVSS 3.1); NVD has not scored it yet. No fixed version is named.

Source:NVD
Post
ImageMagick on Windows hit by high-severity Ghostscript path flaw
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 launches gswin64c.exe by bare name when Ghostscript is not registered (CVE-2026-108693). A malicious gswin64c.exe planted in the working directory runs with ImageMagick's privileges when a PDF, PostScript or EPS file is converted there. VulnCheck, the CNA, rates it 7.0 under CVSS 3.1 (7.3 under CVSS 4.0); NVD has not published its own score. No fixed version is named.

ImageMagick on Windows has an uncontrolled search path vulnerability, tracked as CVE-2026-108693, that can let an attacker run code by planting a fake Ghostscript executable. The CVE record covers ImageMagick 7 through 7.1.2-33 and ImageMagick 6 through 6.9.13-58.
When Ghostscript is not registered on the system, ImageMagick's NTGhostscriptEXE() function launches gswin64c.exe by bare name instead of a full path.
How it works. When Ghostscript is not registered on the system, ImageMagick's NTGhostscriptEXE() function launches gswin64c.exe by bare name instead of a full path. An attacker who places a malicious gswin64c.exe in the working directory gets it executed, with ImageMagick's privileges, when a PDF, PostScript or EPS file is converted there. The input file itself does not need to be malicious.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Severity. VulnCheck, the CVE Numbering Authority that assigned the CVE, rates it 7.0 (high) under CVSS 3.1 and 7.3 (high) under CVSS 4.0. Its vector marks the attack as local, of high complexity and requiring user interaction. NVD has received the record but has not yet published its own score.

Fix status. The affected range includes 7.1.2-33, the newest ImageMagick release as of October 10, and neither the CVE record nor GitHub's advisory (GHSA-92c8-5jfq-j2vj) names a fixed version.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
References. The record links the relevant lines of nt-base.c in the ImageMagick source, a public proof-of-concept repository and VulnCheck's advisory. Researchers Muhammad Ali and Hasan Anwar are credited with finding it.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityimagemagick
More fromNVD
  • WPO365 plugin patches two high-severity WordPress flaws

    Tech · 22h
  • System Informer before 4.0.26241.138 exposed to local privilege escalation

    Tech · 1d
  • LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Tech · 1d
More inTech
  • Anthropic AI Model Submits False Homicide Tip to Philadelphia Police

    Tech · 1d
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    WPO365 plugin patches two high-severity WordPress flaws

    The WPO365 WordPress plugin has patched two high-severity vulnerabilities in versions through 44.1. Both flaws could allow unauthenticated attackers to achieve site takeover or persistent script injection.

  • Tech· 

    System Informer before 4.0.26241.138 exposed to local privilege escalation

    Winsiderss System Informer versions through 4.0.26241.138 contain an incorrect authorization flaw that lets local attackers execute code as SYSTEM from any signed process. Vulncheck rates the issue 7.8 and 8.5.

  • Tech· 

    LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.

  • Tech· 

    PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

  • Tech· 

    IBM Security Verify Access: 4 more vulnerabilities disclosed

    IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.