CVE-2026-25965Disclosure(imagemagick / imagemagick)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch imagemagick imagemagick systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-24); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 3Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure2General1Patch1
2026-02-271
General1
2026-02-281
General1
2026-03-011
Disclosure1
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25965 ImageMagick Path Traversal Vulnerability Enables Local File Disclosure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25965

    Post summary

    The post announces a new ImageMagick path traversal vulnerability (CVE-2026-25965) that allows local file disclosure, with no further details on PoC, exploitation, or patch.

    0002157
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25965: HIGH] ImageMagick's recent security update fixed LFI vulnerability pre 7.1.2-15 & 6.9.13-40. Make sure writing is restricted by adjusting policies to ensure further security.#cve,CVE-2026-25965,#cybersecurity https://cvefind.com/CVE-2026-25965

    Post summary

    ImageMagick’s CVE‑2026‑25965, an LFI flaw, has been addressed by recent updates; users should enforce write restrictions via policy adjustments to maintain security.

    0001062
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-25965 pertains to a path traversal vulnerability in ImageMagick, a widely used open-source software suite for image processing. The core issue arises from how ImageMagick enforces security policies related to file access. Prior to versions 7.1.2-15 and 6.9.13-40, the software applies its security policy checks on the raw, unnormalized filename string **before** the operating system resolves any path traversal sequences (like `../`). #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-25965

    Post summary

    The post details a path traversal vulnerability in ImageMagick that allows unnormalized filenames to bypass security policies, potentially enabling remote code execution or privilege escalation.

    0001050
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25965 (CVSS:8.6, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25965 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-25965, noting its high CVSS score and affected ImageMagick versions, but provides no PoC, exploit, or patch details.

    0000022
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25965 (CVSS:8.6, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25965 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text briefly identifies CVE-2026-25965 with a CVSS score but provides no additional technical or actionable information.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25965 (CVSS:8.6, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25965 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post merely references CVE-2026-25965 with a CVSS score and a link to NVD, without providing any detailed technical, exploit, or mitigation information.

    0000026
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25965 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security p… https://www.cve.org/CVERecord?id=CVE-2026-25965

    Post summary

    The post references CVE‑2026‑25965 affecting ImageMagick before certain releases, but offers no further details on exploitation, patches, or technical specifics.

    00000126
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more