PT-2026-21625 · Unknown+3 · Imagemagick+3

·

CVE-2026-25965

·

Published

2026-02-03

·

Updated

2026-06-17

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-15 ImageMagick versions prior to 6.9.13-40
Description ImageMagick is software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the path security policy is enforced on the raw filename string before the filesystem resolves it. This allows a path traversal, enabling local file disclosure (LFI) even when a policy-secure.xml file is applied. The issue arises because ImageMagick applies security policy checks on the raw, unnormalized filename string before the operating system resolves path traversal sequences. The policy-secure.xml file is used to define security policies.
Recommendations Versions prior to 7.1.2-15 should be updated. Versions prior to 6.9.13-40 should be updated. Adjust policies to restrict writing to further enhance security.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06712
CVE-2026-25965
ECHO-1A7D-AFEC-31FD
GHSA-8JVJ-P28H-9GM7
OESA-2026-1452
OESA-2026-1453
OESA-2026-1454
OESA-2026-1455
OESA-2026-1456
OESA-2026-1457
OPENSUSE-SU-2026:10267-1
OPENSUSE-SU-2026:20337-1
RHSA-2026:5573
SUSE-SU-2026:0851-1
SUSE-SU-2026:0852-1
SUSE-SU-2026:0853-1
USN-8263-1

Affected Products

Imagemagick
Linuxmint
Red Os
Ubuntu