Impact
The vendor’s –concatenate option was implemented without the necessary policy checks, allowing an attacker to choose filenames that traverse directories. This flaw permits the attacker to read or write files in locations that the security policy normally forbids, directly compromising the confidentiality and integrity of protected data. The weakness is an example of path traversal, missing authorization, and policy bypass, as identified by the associated CWE identifiers.
Affected Systems
All publicly available builds of ImageMagick before version 7.1.2‑26 are impacted. The product is identified under the ImageMagick:ImageMagick vendor/product name and includes the library’s image processing functionality.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity while the EPSS score of less than 1% reflects a very low but non‑zero chance of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the execution of the –concatenate command with maliciously constructed filenames, which could be used in any environment that processes untrusted image files, such as web servers, content management systems, or media handling services.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA