CVE-2026-105403
Received Received - Intake

ImageMagick Policy Bypass via Coder Domain Evasion

Vulnerability report for CVE-2026-105403, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick 0
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick before versions 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses 'coder' instead of 'module' as its domain. An attacker can exploit this by providing a crafted image to bypass intended format restrictions, enabling ImageMagick to process blocked file formats.

Detection Guidance

Check ImageMagick version with 'convert --version' or 'magick --version'. If running versions before 6.9.13-56 or 7.x before 7.1.2-31, the system is vulnerable. Review policy files for 'coder' domain usage instead of 'module'.

Impact Analysis

This flaw could allow unauthorized processing of restricted image formats, potentially leading to further security risks such as data exfiltration or execution of malicious code. The attack requires local access but has low complexity and does not need user interaction.

Compliance Impact

This vulnerability allows unauthorized processing of restricted image formats, which could lead to exposure of sensitive data. For GDPR, this may result in unauthorized data processing or disclosure, violating principles of data protection. For HIPAA, it could permit access to protected health information without proper authorization, compromising patient privacy.

Mitigation Strategies

Upgrade ImageMagick to patched versions 6.9.13-56 or 7.1.2-31 or later. Replace any policies using 'coder' domain with 'module' domain to enforce intended restrictions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105403. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart