Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61859

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

A flaw was found in ImageMagick. A local attacker with low privileges can exploit a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows the attacker to read files from paths that are otherwise disallowed by the configured security policy, leading to information disclosure.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Restrict use of the -script option by ensuring untrusted users cannot invoke ImageMagick commands directly. If ImageMagick is used in an automated pipeline, use a wrapper that does not pass the -script flag. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2500896ImageMagick: ImageMagick: Information disclosure via policy bypass in -script operation

EPSS

Процентиль: 3%
0.00131
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVSS3: 3.3
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVSS3: 3.3
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a p ...

CVSS3: 3.3
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 3%
0.00131
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2026-61859