Junglewise Threat Intelligence

CVE-2026-86424: ImageMagick TOCTOU race condition in video decoder

CVE-2026-86424 · Severity: low · CVSS 2.5 · Published 2026-09-07

Technologies: ImageMagick. Vendors: ImageMagick.

Executive brief

ImageMagick is a widely-used image and video processing library. A race condition in its video decoder allows a local attacker with low privileges to bypass write restrictions and potentially write files to policy-restricted directories by replacing symbolic links between security checks and file operations.

Technical details

This is a time-of-check-time-of-use (TOCTOU) race condition with CWE-59 (link following) in the video decoder component. The vulnerability exists because the policy validation logic checks whether a file path is allowed before writing, but a local attacker with low privileges can race-replace a symbolic link between the check and use phases to redirect writes to policy-denied locations. The attack requires local access and high attack complexity due to race condition timing requirements. An attacker can bypass path policy restrictions and write to restricted directories. Patches are available in ImageMagick 7.1.2-30 and 6.9.13-55.

Affected products

  • ImageMagick ImageMagick before 7.1.2-30 and before 6.9.13-55

Timeline

  • 2026-08-23: disclosed: GitHub Security Advisory published
  • 2026-08-23: patched: Patched in 7.1.2-30 and 6.9.13-55
  • 2026-09-07: advisory: CVE-2026-86424 published

References

Related threats