
ImageMagick fixes path-policy bypass that can expose restricted files (CVE-2026-25965)
ImageMagick disclosed a High-severity path-policy bypass where traversal in filenames can read restricted files despite policy-secure.xml; update to 7.1.2-15 or 6.9.13-40.
NewsVulnerabilityOpen Source
24 Feb 2026
