CVE-2026-55628 - ImageMagick: Policy Bypass in concatenate operation due to missing checks
Posted: Wed Jul 01, 2026 9:26 pm
CVE ID: CVE-2026-55628
Published: July 1, 2026
Description: In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
Severity: 0.0 | NA
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-55628
Published: July 1, 2026
Description: In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
Severity: 0.0 | NA
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-55628