Junglewise Threat Intelligence

CVE-2026-25965: ImageMagick path traversal policy bypass in path security policy

CVE-2026-25965 · Severity: high · CVSS 8.6 · Published 2026-02-24

Technologies: ImageMagick, Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Red Hat Enterprise Linux 6, Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-OpenMP-x86 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: Red Hat, ImageMagick, NuGet.

Executive brief

ImageMagick, a widely used tool for processing digital images, contains a security flaw that allows unauthorized access to sensitive files on a server. By using specially crafted file paths, an attacker can bypass security restrictions intended to block access to private system folders. This could lead to the exposure of confidential data or system configuration files, potentially compromising the entire server.

Technical details

A path traversal vulnerability exists in ImageMagick because its path security policy is enforced on raw filename strings before filesystem normalization. An attacker can bypass policy rules (e.g., restrictions on /etc/*) by using unnormalized paths containing traversal sequences (../). While the policy matcher sees the unnormalized string and permits the action, the underlying operating system resolves the path to a restricted file and opens it. This results in Local File Disclosure (LFI). The issue is fixed in versions 7.1.2-15 and 6.9.13-40 by improving path validation, and users are advised to update their policy.xml to explicitly block traversal patterns.

Affected products

  • ImageMagick ImageMagick < 7.1.2-15, < 6.9.13-40
  • Red Hat Red Hat Enterprise Linux Server (v. 7 ELS) 7
  • Red Hat Red Hat Enterprise Linux 6 6

Timeline

  • 2026-02-23: advisory: GitHub Security Advisory published
  • 2026-02-24: disclosed: NVD publication date
  • 2026-03-24: patched: Red Hat released security updates (RHSA-2026:5573)

References

Related threats