---
id: CVE-2026-61859
title: >-
  ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy
  bypass vulnerability in the -script operation due to missing security policy
  checks
summary: >-
  ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy
  bypass vulnerability in the -script operation due to missing security policy
  checks. This allows reading files from paths that are otherwise disallowed by
  the co…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-59
vendor: imagemagick
product: imagemagick
affected:
  - 'imagemagick >= 6.9.13-0, < 6.9.13-51'
  - 'imagemagick >= 7.0.0-0, < 7.1.2-26'
patched:
  - imagemagick 7.1.2-26
published: '2026-07-15'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:36:03.307'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61859'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-script-operation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00168
epssPercentile: 0.05486
ingestedAt: '2026-10-09T12:53:29.240Z'
---

## Overview

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

## Affected

- `imagemagick >= 6.9.13-0, < 6.9.13-51`
- `imagemagick >= 7.0.0-0, < 7.1.2-26`

## Remediation

Upgrade past the affected range:

- `imagemagick 7.1.2-26`
