GHSA-78ww-3q48-4x48MediumCVSS 6.2

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block.

🔗 References (4)