Path traversal in ImageMagick - CVE-2026-49219
Published: May 31, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to path traversal in filename parsing when processing a filename that uses a symlink. A local user can supply a crafted filename to disclose sensitive information.
The issue can bypass configured security policy restrictions on file access.