Impact
The –concatenate option in ImageMagick omitted necessary policy checks, enabling an attacker to use crafted filenames that traverse directories. This allows read or write operations on paths that the security policy normally forbids, effectively bypassing access controls. The flaw includes path traversal (CWE‑73), missing authorization (CWE‑862), and policy bypass (CWE‑1220), and can directly compromise confidentiality and integrity by exposing protected files or altering them.
Affected Systems
All ImageMagick releases prior to version 7.1.2‑26 are vulnerable; the vendor fixed the issue in 7.1.2‑26. The affected product is the ImageMagick image processing library, available under the ImageMagick:ImageMagick vendor/product name.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity while the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can exploit the flaw by invoking the –concatenate command with maliciously crafted file names; this could occur in any context where untrusted image files are processed, such as web servers or media handling services.
OpenCVE Enrichment
Debian DLA
Debian DSA