Back

MEDIUM

ImageMagick: Policy Bypass can read disallowed files

Published Jun 10, 2026

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

Affected products

Remediation

Red Hat statement

This flaw in ImageMagick is rated as Low impact. It allows an attacker with local access and high privileges to bypass security policies through incorrect filename parsing. This could lead to the disclosure of files that are otherwise protected by the system's security configuration.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 10, 2026
Updated Jun 11, 2026
Reserved May 28, 2026
CISA Vulnrichment
Updated Jun 11, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Low
Public date Jun 10, 2026
GHSA-XCJM-WQFF-M669