← Back to CVE search

CVE-2026-55628

ImageMagick

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.

CVSS 5.5EPSS 0.098%Risk 0.55
View source
Published
2026-07-01 19:16:55
Affected versions
<7.1.2-26
Type
Library
Last modified
2026-07-29 21:17:47
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H