Description

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

Severity (CVSS)

Base score4.8
SeverityMedium
VersionCVSS 4.0
VectorCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-59 — Improper Link Resolution Before File Access ('Link Following')

Affected products

VendorProductVersions
ImageMagickImageMagick0 to <7.1.2-26; 7.1.2-26
ImageMagickImageMagick0 to <6.9.13-51; 6.9.13-51

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 16 Jul 2026 07:01 UTC.