Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-68950


ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows reading the mvg file will be affected. Version 7.1.2-12 fixes the issue.


Published

2025-12-30T17:15:43.770

Last Modified

2026-01-06T18:13:53.607

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-674

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application imagemagick imagemagick < 7.1.2-12 Yes

References