Executive brief
ImageMagick is a widely used open-source tool for editing and converting digital images. A flaw in how it processes specific image script files (MSL) could allow an attacker to crash the software or disrupt operations. This could lead to a denial-of-service for applications that rely on ImageMagick to process user-uploaded images.
Technical details
A heap-based use-after-free vulnerability exists in the Magick Scripting Language (MSL) decoder of ImageMagick. The vulnerability is triggered when processing a specially crafted MSL image file, leading to memory corruption. An attacker with the ability to provide a malicious MSL file to the library can cause a denial-of-service (application crash). The issue is identified as CWE-416 and affects versions prior to 7.1.2-23 and 6.9.13-48. Patches have been released in versions 7.1.2-23 and 6.9.13-48 to address the root cause in the MSL decoder.
Affected products
- ImageMagick ImageMagick < 7.1.2-23, < 6.9.13-48
Timeline
- 2026-05-17: advisory: GitHub Security Advisory published
- 2026-06-10: disclosed: NVD publication date