VYPR
Low severity3.3NVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

CVE-2026-61859

CVE-2026-61859

Description

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

Affected products

5

Patches

Vulnerability mechanics

References

2

News mentions

1