Page 1 of 1

CVE-2026-55628 - ImageMagick: Policy Bypass in concatenate operation due to missing checks

Posted: Wed Jul 01, 2026 9:26 pm
by Starburst-David
CVE ID: CVE-2026-55628
Published: July 1, 2026
Description: In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
Severity: 0.0 | NA

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-55628