CVE-2026-106566

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,0
Attack Vector: local
Attack Complexity: high
Privileges Required: high
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none

Description

AI Translation Available

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment variable, allowing a local privileged workflow to overwrite a file with random data. This issue is fixed in version 7.1.2-32.

61

UNIX Symbolic Link (Symlink) Following

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Files Or Directories Modify Files Or Directories
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/ImageMagick/ImageMagick6/commit/11d2af00a948e9ca2919d9a8684d…
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57
https://github.com/ImageMagick/ImageMagick/commit/48e5ce1779fc640a389f0020fd7d9…
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54hm-vrmh-7…