Arbitrary File Read and Remote Code Execution Vulnerability in Piwigo by Piwigo
CVE-2026-85750
What is CVE-2026-85750?
Piwigo, prior to version 16.4.0, is susceptible to a significant vulnerability that enables arbitrary file reading and may lead to remote code execution during image upload handling. This arises from inadequate validation and insecure processing of user-uploaded image files, particularly when utilizing the Imagick library. Attackers can exploit format confusion—posing SVG content as PNGs—to trigger misinterpretation of malicious embedded SVG components referencing local files. Furthermore, the Imagick library's support for Magick Scripting Language (MSL) can be leveraged to process harmful commands, potentially allowing unauthorized file manipulations and code execution on the server, contingent on the system's configuration. This vulnerability has been addressed in Piwigo version 16.4.0.
Affected Version(s)
Piwigo <= 16.3.0
