CVE-2025-55298 | ImageMagick up to 6.9.13-27/7.1.2-1 InterpretImageFilename write-what-where condition (GHSA-9ccg-6pjw-x645 / WID-SEC-2025-1906)
A vulnerability described as critical has been identified in ImageMagick up to 6.9.13-27/7.1.2-1. This affects the function InterpretImageFilename. Such manipulation leads to write-what-where condition.
This vulnerability is traded as CVE-2025-55298. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.