Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105083— ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE

Quick assessment

Affected
ImageMagick ImageMagick
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ImageMagick 7.1.2-32 之前版本及 6.9.13-57 之前版本中,LoadPolicyCache 函数存在一个策略绕过漏洞。当 policy.xml 文件使用非标准的 DOCTYPE 声明时,该漏洞会导致安全策略规则被静默跳过。具体来说,若 DOCTYPE 声明未以 "]>" 结尾,解析器将会读取并消耗文件的其余部分,从而导致所有策略规则未被应用,使得原本受限制的操作变为允许执行。

CVSS 3.9 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105083

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE
Source: CVE Program / CVE List V5
Vulnerability Description
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ImageMagick ImageMagick 7.0.0-0 ~ 7.1.2-32 -

II. Public POCs for CVE-2026-105083

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105083

请登录查看更多情报信息。

Other References for CVE-2026-105083 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105083

No comments yet


Leave a comment