This vulnerability affects applications that:
imagick as the image library)resize() methodtext() method with user-controlled text content or optionsAn attacker can:
Upgrade to v4.6.2 or later.
gd, the default handler), which is not affected by either vulnerabilitygetRandomName() when using the move() method, or use the store() method, which automatically generates safe filenamespreg_replace('/[^a-zA-Z0-9\s.,!?-]/', '', $text) and validate/restrict text options{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2025-07-28T16:08:20Z",
"nvd_published_at": "2025-07-28T15:15:26Z",
"severity": "CRITICAL"
}