ImageMagick: Policy Bypass in PSD decoder
Moderate severity
GitHub Reviewed
Published
May 16, 2026
in
ImageMagick/ImageMagick
•
Updated May 18, 2026
Description
Published to the GitHub Advisory Database
May 18, 2026
Reviewed
May 18, 2026
Last updated
May 18, 2026
Due to a missing check in the PSD decoder it would be possible to bypass the
list-lengthresource policy when decoding a PSD image. Other security limits would still apply.References