CVE-2026-61859: ImageMagick

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

Affected products

  • ImageMagick ImageMagick: from 6.9.13-0, before 6.9.13-51 (fixed in 6.9.13-51); from 7.0.0-0, before 7.1.2-26 (fixed in 7.1.2-26)

Published 2026-07-15. Last modified 2026-10-09.