{"id":"JLSEC-2026-913","details":"ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.","modified":"2026-07-30T18:23:50.561785406Z","published":"2026-07-30T16:02:27.435Z","upstream":["CVE-2024-41817","EUVD-2024-39202"],"database_specific":{"sources":[{"imported":"2026-07-30T14:08:43.908Z","modified":"2026-06-17T07:48:17.267Z","published":"2024-07-29T16:15:05.360Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-41817","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41817","database_specific":{"status":"Analyzed"},"id":"CVE-2024-41817"},{"html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39202","id":"EUVD-2024-39202","imported":"2026-07-30T14:08:56.185Z","modified":"2024-08-02T04:46:53Z","published":"2024-07-29T15:53:17Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2024-39202"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://github.com/ImageMagick/ImageMagick/blob/3b22378a23d59d7517c43b65b1822f023df357a0/app-image/AppRun#L11-L14"},{"type":"WEB","url":"https://github.com/ImageMagick/ImageMagick/commit/6526a2b28510ead6a3e14de711bb991ad9abff38"},{"type":"WEB","url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8"}],"affected":[{"package":{"name":"ImageMagick_jll","ecosystem":"Julia","purl":"pkg:julia/ImageMagick_jll?uuid=c73af94c-d91f-53ed-93a7-00f77d67a9d7"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.1.0+0"},{"fixed":"7.1.1047+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-913.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}