Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Published: 2026-10-07
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure and Potential Crash
Action: Apply Patch
AI Analysis

Impact

ImageMagick contains a flaw that allows a crafted local encoding operation to bypass internal security policy checks in the CUT encoder. This permits the attacker to read data that policy should forbid and can also trigger an application crash. The weakness is a breach of least privilege, leading to unauthorized information disclosure and possible denial of service, as indicated by the CWE-284 and CWE-400 identifiers.

Affected Systems

The affected products are ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. Any installations running these earlier releases are susceptible to the policy bypass in the CUT encoder.

Risk and Exploitability

The CVSS score is 4, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a local crafted encoding operation performed by a user who can input data to the CUT encoder. If the attacker can execute such an operation, they may read restricted data or cause a crash, both of which can lead to system instability or leakage of sensitive information.

Generated by OpenCVE AI on October 7, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ImageMagick version 7.1.2-31 or later
  • Upgrade to ImageMagick 6.9.13-56 or later
  • If upgrading is not immediately possible, disable or restrict use of the CUT encoder until a patch is applied

Generated by OpenCVE AI on October 7, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick

Wed, 07 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Title ImageMagick: Policy Bypass in CUT encoder
Weaknesses CWE-284
CWE-400
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T16:58:28.876Z

Reserved: 2026-10-06T20:31:59.018Z

Link: CVE-2026-106580

cve-icon Vulnrichment

Updated: 2026-10-07T16:58:19.641Z

cve-icon NVD

Status : Received

Published: 2026-10-07T16:17:44.560

Modified: 2026-10-07T17:16:52.713

Link: CVE-2026-106580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T17:45:14Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption