← Back to CVE List
CVE-2026-106579NVD
Vulnerability Summary
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
CVSS v3.1 Base Metrics — Score 6.2 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/ImageMagick/ImageMagick/commit/82f373fedb3425c83a239103ab86f4fa86fd49ac
- https://github.com/ImageMagick/ImageMagick/commit/dcdbbf4278fab20a32a4ad80e64cb95c368ca8dd
- https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vcjj-32hg-qpx5
- https://github.com/ImageMagick/ImageMagick6/commit/ac85c8e0a319b1eaf4c3d05d326605f5bae723d6
- https://github.com/ImageMagick/ImageMagick6/commit/c54667bfe605ebdc17c23cb70a26dbe00b338222
- https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56