CVE-2026-106580: ImageMagick: Policy Bypass in CUT encoder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-56
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using ImageMagick versions earlier than 7.1.2-31 or 6.9.13-56 are affected when a local encoding operation can be made to use the CUT encoder. The issue requires local access or local control of the encoding operation.
What can an attacker achieve?
A crafted local encoding operation may read data that the configured ImageMagick security policy is intended to deny. It can also cause ImageMagick to crash, resulting in a local availability impact.
What should be done if patching cannot happen immediately?
Prevent untrusted or unauthorized local users and processes from performing CUT encoding operations, particularly where ImageMagick security policies are relied on to restrict data access. Upgrading to 7.1.2-31 or 6.9.13-56 is the documented fix.