Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Security policy bypass leading to possible code execution
Action: Patch Now
AI Analysis

Impact

ImageMagick versions prior to 6.9.13‑56 and 7.x before 7.1.2‑31 allow a policy bypass when a policy uses a coder domain instead of a module domain, enabling an attacker to supply a crafted image that causes the software to process file formats that an administrator intended to block. The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. Because the security policy is respected only after image parsing, the vulnerability can lead to processing of malicious image formats that could lead to code execution if those formats invoke arbitrary code execution handlers. The impact therefore ranges from inadvertent processing of disallowed formats to potential execution of attacker‑controlled code, depending on the policies active in the environment.

Affected Systems

Any system running ImageMagick that has not applied the official update to at least 6.9.13‑56 or 7.1.2‑31 is affected. The vulnerability is present in the ImageMagick core product; administrators should review all deployments using ImageMagick for image processing, ad‑hoc scripts, web applications, or other services that invoke the ImageMagick library.

Risk and Exploitability

The CVSS score of 6.9 places the vulnerability in the moderate range, but because no EPSS value is provided the likelihood of exploitation is unclear. The vulnerability is not yet listed in the CISA KEV catalog, which reduces the urgency but does not eliminate risk. The likely attack vector is remote: an attacker can send a crafted image through a web upload or other interface that internally calls ImageMagick. If the system relies on coder‑based policies, the attacker can bypass those restrictions, causing ImageMagick to process the previously blocked format and potentially execute embedded code or otherwise compromise the host.

Generated by OpenCVE AI on October 8, 2026 at 15:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑31 or newer (or to 6.9.13‑56 or newer for legacy 6.x releases).
  • Update or re‑configure security policies to use the module domain instead of the coder domain to enforce restrictions correctly.
  • Audit dependent applications and services that call ImageMagick, ensuring they implement the latest security patches and validate image inputs before processing.

Generated by OpenCVE AI on October 8, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block.
Title ImageMagick before 7.1.2-31 Security Policy Bypass via Coder Domain
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-863
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:07:44.406Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105403

cve-icon Vulnrichment

Updated: 2026-10-08T17:07:39.575Z

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:33.637

Modified: 2026-10-08T17:17:12.247

Link: CVE-2026-105403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:00:06Z

Weaknesses