Junglewise Threat Intelligence

CVE-2026-49219: ImageMagick policy bypass via incorrect filename parsing

CVE-2026-49219 · Severity: medium · CVSS 5.5 · Published 2026-06-10

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: ImageMagick, NuGet.

Executive brief

ImageMagick is a software suite used for displaying, converting, and editing image files. A security flaw in how it handles filenames allows an attacker to bypass security policies and read sensitive files on the system that should be restricted. This could lead to the unauthorized exposure of private data or system configuration files.

Technical details

A policy bypass vulnerability exists in ImageMagick due to incorrect parsing of filenames when handling symbolic links. An attacker with local access and low privileges can exploit this flaw to read files that are otherwise disallowed by the application's security policy (CWE-863, CWE-22). The root cause is a failure to properly neutralize path elements or validate symlink targets against the defined security policy. This can result in the exposure of sensitive information (CWE-200). The vulnerability is addressed in Magick.NET version 14.14.0.

Affected products

  • ImageMagick Magick.NET-Q16-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-x86 < 14.14.0
  • ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-x86 < 14.14.0
  • ImageMagick Magick.NET-Q8-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.14.0
  • ImageMagick Magick.NET-Q8-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q8-x64 < 14.14.0
  • ImageMagick Magick.NET-Q8-x86 < 14.14.0

Timeline

  • 2026-05-30: disclosed
  • 2026-06-10: advisory: NVD publication date
  • 2026-06-25: patched: GitHub Advisory reviewed and updated

References

Related threats