The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/
{
"github_reviewed_at": "2026-05-21T21:49:09Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-323",
"CWE-330"
],
"nvd_published_at": null,
"severity": "LOW"
}