CVE-2026-56377: ImageMagick - Policy Bypass via Incorrect Path Validation
ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56377?
CVE-2026-56377 has a severity rating of low, with a score of 3.3.
How does CVE-2026-56377 affect ImageMagick?
CVE-2026-56377 allows attackers to bypass path policy restrictions and create or truncate files disallowed by security policies.
What is the risk associated with CVE-2026-56377?
CVE-2026-56377 has a risk rating of 18, indicating a low level of risk for exploitation.
How do I fix CVE-2026-56377?
To mitigate CVE-2026-56377, upgrade ImageMagick to version 7.1.2-24 or later.
Which versions of ImageMagick are affected by CVE-2026-56377?
CVE-2026-56377 affects versions of ImageMagick before 7.1.2-24.