CVE-2026-61859Low· 3.3▾ SunlitImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the co…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.
imagemagick >= 6.9.13-0, < 6.9.13-51imagemagick >= 7.0.0-0, < 7.1.2-26Upgrade past the affected range:
imagemagick 7.1.2-26Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86422Low· 3.3ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions
CVE-2026-86424Low· 2.5ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps
CVE-2026-105402Medium· 5.3Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-105398Medium· 5.1Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-105399Medium· 5.3Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-105401Medium· 5.3Rejected reason: This CVE ID has been rejected as a duplicate.