๐Ÿ” CVE Alert

CVE-2026-105083

LOW 3.9

ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE

CVSS Score
3.9
EPSS Score
0.0%
EPSS Percentile
0th

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

CWE CWE-693
Vendor imagemagick
Product imagemagick
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for imagemagick imagemagick

Be the first to know when new low vulnerabilities affecting imagemagick imagemagick are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

ImageMagick / ImageMagick
7.0.0-0 < 7.1.2-32 0 < 6.9.13-57

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j github.com: https://github.com/ImageMagick/ImageMagick/commit/1926ccf119141c26274c120d1899dffae19b0c71 github.com: https://github.com/ImageMagick/ImageMagick/commit/399d4bd3b081f44c7fef78153f65e8cdebed9f1a github.com: https://github.com/ImageMagick/ImageMagick6/commit/da6022b2efe6cce8a2fd8f9e51188a45a3b9d558 github.com: https://github.com/ImageMagick/ImageMagick6/commit/402ebc5353e569234908962cbdf451531ff66a57 github.com: https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/MagickCore/policy.c#L1138-L1145 github.com: https://github.com/ImageMagick/ImageMagick vulncheck.com: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-security-policy-bypass-via-policy-xml-doctype

Credits

Yanhaoxi