PT-2026-48567 · Unknown+1 · Imagemagick+1

CVE-2026-49219

·

Published

2026-05-30

·

Updated

2026-07-08

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.9.13-48 ImageMagick versions prior to 7.1.2-24
Description Incorrect parsing of the filename allows a policy bypass, enabling the reading of files disallowed by a security policy through the use of a symlink (a symbolic link that acts as a reference to another file or directory).
Recommendations Update to version 6.9.13-48. Update to version 7.1.2-24.

Exploit

Fix

DoS

Path traversal

Information Disclosure

Incorrect Authorization

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10447
CVE-2026-49219
ECHO-4821-3282-7AF1
GHSA-XCJM-WQFF-M669
OESA-2026-2555
OPENSUSE-SU-2026:11061-1

Affected Products

Imagemagick
Red Os