CVE-2026-106579 PUBLISHED

ImageMagick: Policy Bypass when using coder as the domain.

Assigner: GitHub_M
Reserved: 06.10.2026 Published: 07.10.2026 Updated: 07.10.2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.2

Product Status

Vendor ImageMagick
Product ImageMagick
Versions
  • Version < 6.9.13-56 is affected
  • Version >= 7.0.0, < 7.1.2-31 is affected

References

Problem Types

  • CWE-551: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization CWE