Junglewise Threat Intelligence

ImageMagick policy bypass in APNG encoder and delegates

Severity: low · CVSS 3.3 · Published 2026-07-24

Technologies: ImageMagick,versions: Magick.NET-Q8-OpenMP-x64. Vendors: ImageMagick.

Executive brief

A security flaw in ImageMagick's image processing library could allow a local user to bypass security policies and write files to unauthorized locations on the system. This affects applications using the Magick.NET library to process APNG images. While the risk is low, it could potentially be used to overwrite sensitive configuration files or application data if an attacker has local access.

Technical details

A policy bypass vulnerability exists in ImageMagick's APNG encoder and external delegates due to missing authorization checks (CWE-862) and improper link resolution (CWE-59). A local attacker with low privileges can exploit this to write files to paths that should be restricted by the ImageMagick security policy. The vulnerability is triggered during the encoding of APNG images or when utilizing specific external delegates. The issue is addressed in Magick.NET version 14.15.0.

Affected products

  • ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
  • ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
  • ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
  • ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
  • ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
  • ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
  • ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
  • ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
  • ImageMagick Magick.NET-Q16-arm64 < 14.15.0
  • ImageMagick Magick.NET-Q16-x64 < 14.15.0
  • ImageMagick Magick.NET-Q16-x86 < 14.15.0
  • ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
  • ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
  • ImageMagick,versions: Magick.NET-Q8-OpenMP-x64 < 14.15.0
  • ImageMagick Magick.NET-Q8-arm64 < 14.15.0
  • ImageMagick Magick.NET-Q8-x64 < 14.15.0
  • ImageMagick Magick.NET-Q8-x86 < 14.15.0

Timeline

  • 2026-06-26: disclosed: Initial disclosure by dlemstra
  • 2026-07-24: advisory: GitHub Advisory published
  • 2026-07-24: patched: Fix released in Magick.NET 14.15.0

References