CVE-2026-106566
Received Received - Intake

ImageMagick Symlink Cleanup Flaw Allows File Overwrite

Vulnerability report for CVE-2026-106566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment variable, allowing a local privileged workflow to overwrite a file with random data. This issue is fixed in version 7.1.2-32.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick < 6.9.13-57
ImageMagick ImageMagick >= 7.0.0, < 7.1.2-32

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick before version 7.1.2-32 involves improper handling of the MAGICK_SHRED_PASSES environment variable during delegate symlink cleanup. A local privileged user could exploit this to overwrite files with random data by manipulating symlinks.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick. If it is prior to 7.1.2-32, the system is vulnerable. Run: identify -version or magick -version to check the version.

Impact Analysis

If you use a vulnerable version of ImageMagick, a local attacker with privileges could overwrite important files on your system with random data, potentially causing data loss or system instability.

Compliance Impact

This vulnerability primarily impacts data integrity by allowing unauthorized overwriting of files with random data. While it does not directly expose sensitive data, it could lead to non-compliance with GDPR or HIPAA if critical files (e.g., logs, backups) are corrupted. Organizations relying on secure file deletion processes may fail to meet data protection requirements.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-32 or later. Remove unnecessary privileges for local users and avoid running ImageMagick in privileged contexts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart