ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate severity
GitHub Reviewed
Published
Jun 26, 2026
in
ImageMagick/ImageMagick
•
Updated Jul 24, 2026
Description
Published by the National Vulnerability Database
Jul 1, 2026
Published to the GitHub Advisory Database
Jul 24, 2026
Reviewed
Jul 24, 2026
Last updated
Jul 24, 2026
The
-concatenateoperation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.References