CVE-2026-86424 - ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
CVE ID :CVE-2026-86424
Published : Sept. 7, 2026, 12:53 p.m. | 11 minutes ago
Description :ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 7, 2026, 12:53 p.m. | 11 minutes ago
Description :ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...