Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-61858

Опубликовано: 11 июл. 2026
Источник: nvd
CVSS3: 3.3
CVSS3: 5.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия до 6.9.13-51 (исключая)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 7.0.0-0 (включая) до 7.1.2-26 (исключая)

EPSS

Процентиль: 16%
0.00246
Низкий

3.3 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 3.3
ubuntu
21 день назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

CVSS3: 3.3
redhat
21 день назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

CVSS3: 3.3
debian
21 день назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in ...

CVSS3: 3.3
github
20 дней назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 16%
0.00246
Низкий

3.3 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-59