GHSA-9r9r-c7x8-qp3rLowCVSS 3.9

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in...

Published
October 3, 2026
Last Modified
October 3, 2026

🔗 CVE IDs covered (1)

📋 Description

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

🔗 References (10)