Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61859

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package
imagemagickno-dsatrixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27 (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012 (6.9.13-51)

EPSS

Процентиль: 3%
0.00124
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVSS3: 3.3
redhat
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVSS3: 3.3
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVSS3: 3.3
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 3%
0.00124
Низкий