Skip to main content

CVE-2025-53101

7.4
HIGHCVSS v3.1 Base Score
0.35%
LOW RiskEPSS (58th percentile)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue.

Published: 7/14/2025
Modified: 11/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Score (Exploitation Probability)

0.35%LOW Exploitation Risk
58th percentile

This vulnerability has a 0.35% probability of being exploited in the next 30 days, ranking higher than 58% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-124)

Similar SeverityHIGH