Executive brief
ImageMagick is a software suite used for creating, editing, and converting images. A security flaw in its script processing feature allows users to bypass established security policies. This could allow an attacker with local access to read files or data that the system's security configuration was intended to protect.
Technical details
A policy bypass vulnerability exists in ImageMagick's '-script' operation due to missing security checks. The root cause is improper access control (CWE-284) and improper link resolution (CWE-59) within the script processing logic. An attacker with local access and low privileges can exploit this to read files from paths that should be restricted by the ImageMagick security policy. This vulnerability affects various Magick.NET distributions and has been addressed in version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-x86 < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-arm64 < 14.15.0
- ImageMagick, versions: '< 14.15.0' Magick.NET-Q8-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-x86 < 14.15.0
Timeline
- 2026-06-26: disclosed: Initial disclosure by developer
- 2026-07-24: advisory: GitHub Advisory published
- 2026-07-24: patched: Fix released in Magick.NET 14.15.0