Impact
ImageMagick versions before 7.1.2-26 and 6.9.13-51 contain a policy bypass flaw in the -script operation because security policy checks are omitted. This weakness allows an attacker to read files from paths that the configured security policy normally prohibits. The vulnerability is a direct example of unauthorized privilege use (CWE-59) and an authorization bypass that can be achieved using user supplied input (CWE-639). If exploited, it can lead to disclosure of sensitive or restricted data, which may undermine confidentiality of the system.
Affected Systems
The affected product is ImageMagick, specifically version 7.1.2-26 or earlier, and the 6.9.13-x line prior to 6.9.13-51. No additional vendor information is provided beyond the ImageMagick designation.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score being less than 1% signifies a low likelihood of exploitation at present. The vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is likely tied to the execution of the -script operation within a context that processes untrusted image content; the attacker may craft a script that references disallowed files, leveraging the missing policy enforcement. As no additional prerequisites or conditions are described, the exploit appears straightforward to those who can trigger the script operation on a vulnerable installation.
OpenCVE Enrichment
Debian DLA