CVE-2026-25965
Last modified
CVE-2026-25965 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | < 6.9.13-40 |
| Imagemagick | Imagemagick | >= 7.0.0-0, < 7.1.2-15 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-25965?
How severe is CVE-2026-25965?
How do I fix CVE-2026-25965?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2596Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-25960vLLM is an inference and serving engine for large language m…9.8
- CVE-2026-25961SumatraPDF is a multi-format reader for Windows. In 3.5.0 th…7.5
- CVE-2026-25962MarkUs is a web application for the submission and grading o…6.5
- CVE-2026-25963Fleet is open source device management software. In versions…6.5
- CVE-2026-25964Tandoor Recipes is an application for managing recipes, plan…4.9
- CVE-2026-25966ImageMagick is free and open-source software used for editin…7.8
- CVE-2026-25967ImageMagick is free and open-source software used for editin…7.5
- CVE-2026-25968ImageMagick is free and open-source software used for editin…9.8
- CVE-2026-25969ImageMagick is free and open-source software used for editin…7.5
- CVE-2026-2597Crypt::SysRandom::XS versions before 0.010 for Perl is vulne…7.5
- CVE-2026-25970ImageMagick is free and open-source software used for editin…7.5
Are you affected by CVE-2026-25965?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
