ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the -concatenate operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
{
"license": "CC-BY-4.0",
"sources": [
{
"database_specific": {
"status": "Deferred"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55628",
"id": "CVE-2026-55628",
"imported": "2026-07-30T14:10:36.080Z",
"modified": "2026-07-29T21:17:47.470Z",
"published": "2026-07-01T19:16:55.707Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55628"
},
{
"html_url": "https://github.com/advisories/GHSA-82mp-vp5c-9pf7",
"id": "GHSA-82mp-vp5c-9pf7",
"imported": "2026-07-30T14:09:06.109Z",
"modified": "2026-07-24T14:06:42Z",
"published": "2026-07-24T14:06:39Z",
"url": "https://api.github.com/advisories/GHSA-82mp-vp5c-9pf7"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41112",
"id": "EUVD-2026-41112",
"imported": "2026-07-30T14:08:50.755Z",
"modified": "2026-07-29T20:30:01Z",
"published": "2026-07-01T18:16:23Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-41112"
}
]
}