Policy Bypass Vulnerability in ImageMagick by ImageMagick Developers
CVE-2026-105823

2.1LOW

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105823?

ImageMagick versions prior to 6.9.13-56 and 7.x before 7.1.2-31 exhibit a serious flaw in the CUT encoder due to a lack of proper security policy checks. This vulnerability allows attackers to bypass the configured security policies by supplying specially crafted input to the CUT encoder. This could result in the application crashing and could potentially lead to the exposure of sensitive data. It is crucial for users to update to the recommended versions to mitigate this risk and ensure application integrity.

Affected Version(s)

ImageMagick 0 < 7.1.2-31

ImageMagick 0 < 6.9.13-56

ImageMagick 7.1.2-31

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.