VYPR
Low severity3.3NVD Advisory· Published Jul 11, 2026· Updated Jul 14, 2026

CVE-2026-61858

CVE-2026-61858

Description

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

Affected products

4

Patches

Vulnerability mechanics

References

2

News mentions

1