---
id: CVE-2026-105823
title: >-
  ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy
  check in the CUT encoder, allowing configured security policies to be bypassed
summary: >-
  ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy
  check in the CUT encoder, allowing configured security policies to be
  bypassed. Attackers can supply crafted input processed by the CUT encoder to
  crash the app…
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'
cwe:
  - CWE-284
vendor: ImageMagick
product: ImageMagick
affected:
  - ImageMagick < 7.1.2-31
  - ImageMagick < 6.9.13-56
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:50:49.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105823'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-cut-encoder
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T18:12:37.554456Z'
ingestedAt: '2026-10-08T14:47:16.362Z'
---

## Overview

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
