CVE-2016-3714: ImageMagick Improper Input Validation Vulnerability

High severity, CVSS 8.4. Actively exploited: in CISA KEV since 2024-09-09. EPSS: 97.5% chance of exploitation in the next 30 days.

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • ImageMagick ImageMagick: up to and including 6.9.3-9; version 7.0.0-0 only; version 7.0.1-0 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2016-05-05. Last modified 2026-06-17.