Summary
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Advisory details
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
References
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-54629
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
- CRITICALCVE-2026-50006
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- HIGHCVE-2026-72795
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
- MEDIUMCVE-2026-72796
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
- MEDIUMCVE-2026-72797
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers