Executive brief
ImageMagick is a widely-used image and video processing library. A race condition in its video decoder allows a local attacker with low privileges to bypass write restrictions and potentially write files to policy-restricted directories by replacing symbolic links between security checks and file operations.
Technical details
This is a time-of-check-time-of-use (TOCTOU) race condition with CWE-59 (link following) in the video decoder component. The vulnerability exists because the policy validation logic checks whether a file path is allowed before writing, but a local attacker with low privileges can race-replace a symbolic link between the check and use phases to redirect writes to policy-denied locations. The attack requires local access and high attack complexity due to race condition timing requirements. An attacker can bypass path policy restrictions and write to restricted directories. Patches are available in ImageMagick 7.1.2-30 and 6.9.13-55.
Affected products
- ImageMagick ImageMagick before 7.1.2-30 and before 6.9.13-55
Timeline
- 2026-08-23: disclosed: GitHub Security Advisory published
- 2026-08-23: patched: Patched in 7.1.2-30 and 6.9.13-55
- 2026-09-07: advisory: CVE-2026-86424 published