Impact
ImageMagick before version 7.1.2‑26 contains a policy bypass that allows the APNG encoder to write files to any path without enforcing the configured policy rules due to missing validation checks. This flaw is a form of improper access control, as the product permits a malicious actor to create or overwrite files in locations that should be protected, potentially including configuration files, system binaries, or web‑root directories. Consequently, an attacker could tamper with critical files or plant malicious executables, as the weakness is marked by CWE‑22 and CWE‑59.
Affected Systems
The affected product is ImageMagick released by ImageMagick. All versions older than 7.1.2‑26 are vulnerable; updating to 7.1.2‑26 or later removes the flaw.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must cause the target system to process an APNG image—this could happen locally or via a component that performs image conversion—so the attack vector is likely local or application‑level. Because the flaw enables arbitrary file writes, it could be leveraged for privilege escalation or the execution of malicious code if trusted files are overwritten.
OpenCVE Enrichment
Debian DLA