ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows reading the mvg file will be affected. Version 7.1.2-12 fixes the issue.
{
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68950.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-12"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T15:14:54Z"
[
{
"id": "CVE-2025-68950-6231e2a4",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"213328673569520581352047133926445811912",
"3556326905722506442906296695240234989",
"487170900548079139867774542807118714",
"57863189631568782342065078741831770119"
]
},
"source": "https://github.com/imagemagick/imagemagick/commit/204718c2211903949dcfc0df8e65ed066b008dec",
"target": {
"file": "MagickCore/draw.c"
}
},
{
"id": "CVE-2025-68950-f240fd38",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 12304.0,
"function_hash": "319136154103146613798415827121954676538"
},
"source": "https://github.com/imagemagick/imagemagick/commit/204718c2211903949dcfc0df8e65ed066b008dec",
"target": {
"function": "DrawPrimitive",
"file": "MagickCore/draw.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68950.json"