rootpwn

low · CVSS v3 3.9 · CVSS v4 1.8

CVE-2026-105083

ImageMagick versions prior to 7.1.2-32 and 6.9.13-57 can silently ignore security policy rules when policy.xml uses an alternate DOCTYPE tha

Overview

ImageMagick versions prior to 7.1.2-32 and 6.9.13-57 can silently ignore security policy rules when policy.xml uses an alternate DOCTYPE that does not end with "]>", allowing restricted operations to be performed. This policy bypass can enable attackers to execute actions normally blocked by ImageMagick’s security policies. The vulnerability is low severity but still poses a risk to systems that rely on strict policy enforcement.

Description

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

Impact

Confidentiality: attackers may read or modify files that should be protected. Integrity: unauthorized image transformations or command execution could alter system state. Availability: potential for resource exhaustion if malicious operations are performed. Defenders using ImageMagick in web services, media servers, or content pipelines are impacted.

Remediation

Upgrade ImageMagick to the latest release (>=7.1.2-32 or >=6.9.13-57). Verify that policy.xml uses a standard DOCTYPE ending with "]>". Restrict policy.xml to trusted locations and enforce file permissions. Consider disabling or limiting the use of policy.xml for untrusted image sources.

Risk context

The CVSS v3 score of 3.9 and low severity rating indicate a moderate risk; however, the lack of an EPSS score means the vulnerability may not be widely exploited yet. Defenders should still apply the patch promptly to eliminate the policy bypass.

Affected products

  • ImageMagick 7.1.2-32
  • ImageMagick 6.9.13-57
  • ImageMagick 7.x
  • ImageMagick 6.x

Scores

Severity
low
CVSS v2
3.4
CVSS v3
3.9
CVSS v4
1.8
EPSS
—

ImageMagick policy-bypass DOCTYPE low-severity image-processing

← All CVEs