CVE-2026-106579
Received Received - Intake

Policy Bypass in ImageMagick via Crafted Image

Vulnerability report for CVE-2026-106579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick < 6.9.13-56
ImageMagick ImageMagick >= 7.0.0, < 7.1.2-31

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-551 If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick allows a crafted image to bypass a security policy that uses the 'coder' domain. The issue occurs because the policy check incorrectly validates the coder authorization, potentially allowing restricted data to be read. The flaw exists in versions prior to 7.1.2-31 and 6.9.13-56.

Detection Guidance

To detect this vulnerability, check the installed ImageMagick version using 'convert --version' or 'magick --version'. If the version is below 7.1.2-31 or 6.9.13-56, the system is vulnerable. Additionally, review ImageMagick policy files for improper coder domain configurations.

Impact Analysis

An attacker could exploit this to read data that should be restricted by the ImageMagick security policy. The attack requires local access but no special privileges or user interaction. It primarily impacts confidentiality by allowing unauthorized data access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements for data protection such as GDPR or HIPAA. Organizations using vulnerable versions may face compliance risks due to potential data exposure.

Mitigation Strategies

Update ImageMagick to version 7.1.2-31 or later for ImageMagick 7, or 6.9.13-56 or later for ImageMagick 6. This addresses the policy bypass vulnerability in coder domains.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106579. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart