ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2 | Vendor Advisory |
| https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-apng-encoder | Broken Link |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-11 14:16
Updated : 2026-07-14 15:17
NVD link : CVE-2026-61858
Mitre link : CVE-2026-61858
CVE.ORG link : CVE-2026-61858
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
