ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate severity
GitHub Reviewed
Published
Jun 26, 2026
in
ImageMagick/ImageMagick
•
Updated Jul 24, 2026
Description
Published to the GitHub Advisory Database
Jul 24, 2026
Reviewed
Jul 24, 2026
Last updated
Jul 24, 2026
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
References