PT-2026-104477 · Imagemagick · Imagemagick

·

CVE-2026-105083

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

3.9

Low

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105083

Affected Products

Imagemagick