CVE-2026-106566
MEDIUM
4,0
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: high
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none
Description
AI Translation Available
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment variable, allowing a local privileged workflow to overwrite a file with random data. This issue is fixed in version 7.1.2-32.
61
UNIX Symbolic Link (Symlink) Following
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Files Or Directories
Modify Files Or Directories
Applicable Platforms
All platforms may be affected
https://github.com/ImageMagick/ImageMagick6/commit/11d2af00a948e9ca2919d9a8684d…
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57
https://github.com/ImageMagick/ImageMagick/commit/48e5ce1779fc640a389f0020fd7d9…
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54hm-vrmh-7…