You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
Low severity
GitHub Reviewed
Published
Jun 26, 2026
in
ImageMagick/ImageMagick
•
Updated Jul 24, 2026
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Learn more on MITRE.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
References