Low severity3.3NVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
CVE-2026-61859
CVE-2026-61859
Description
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.
Affected products
5cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: >=6.9.13-0,<6.19.13-51
- (no CPE)range: <7.1.2-26, <6.9.13-51
- osv-coords3 versionspkg:apk/chainguard/imagemagick-6pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 6.9.13.51-r0+ 2 more
- (no CPE)range: < 6.9.13.51-r0
- (no CPE)range: < 7.1.2.0-160000.13.1
- (no CPE)range: < 7.1.2.27-3.1
Patches
Vulnerability mechanics
References
2- github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398nvdVendor Advisory
- www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-script-operationnvdThird Party Advisory
News mentions
1- ImageMagick: 14 Vulnerabilities Including Memory Leaks and DoS Flaws Disclosed TogetherVypr Intelligence · Jul 16, 2026