Junglewise Threat Intelligence

CVE-2026-61859: ImageMagick policy bypass in -script operation

CVE-2026-61859 · Severity: low · CVSS 3.3 · Published 2026-07-15

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick, a widely used software suite for editing and processing images, contains a security flaw in its script processing feature. This vulnerability allows a user with local access to bypass established security policies and read sensitive files that should normally be restricted. While the risk is limited to users who already have access to the system, it could lead to the unauthorized exposure of internal configuration or data files.

Technical details

A policy bypass vulnerability exists in ImageMagick's '-script' operation due to missing security policy checks. The root cause is an improper access control mechanism (CWE-284) and improper link resolution (CWE-59) that fails to validate file paths against the configured security policy when executing scripts. An attacker with local access and low privileges can exploit this to read files from paths that are explicitly disallowed by the system's security policy. The issue is addressed in ImageMagick versions 7.1.2-26 and 6.9.13-51.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26, < 6.9.13-51

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: NVD publication date

References

Related threats