Executive brief
ImageMagick, a widely used software suite for editing and converting images, contains a flaw in how it enforces security policies regarding file access. An attacker can exploit this to create or overwrite files on the system that should be protected by the software's security boundaries. This could lead to unauthorized data modification or the disruption of services that rely on ImageMagick for automated image processing.
Technical details
A path traversal vulnerability (CWE-22) exists in ImageMagick due to an incorrect policy check during file operations. The software fails to properly validate pathnames against configured security policies, which are often used in sandboxed environments to restrict write access. An attacker with local access or the ability to influence image conversion parameters can bypass these path policy restrictions to create or truncate arbitrary files. The vulnerability also involves potential Time-of-check Time-of-use (TOCTOU) race conditions (CWE-367). The issue is resolved in versions 7.1.2-24 and 6.9.13-48.
Affected products
- ImageMagick ImageMagick < 7.1.2-24, < 6.9.13-48
Timeline
- 2026-05-30: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date