Vulnerability record · CVE-2016-3714 · published 5 May 2016
CVE-2016-3714: ImageMagick coders allow command execution via crafted image
Imagemagick · Imagemagick
ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 fail to validate input in multiple coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT), allowing shell metacharacters in a crafted image to be passed to the shell. This is the flaw known as ImageTragick and it matters because image processing is often exposed to untrusted files.
Description
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score and allows remote code execution through crafted images.
What it is
ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 fail to validate input in multiple coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT), allowing shell metacharacters in a crafted image to be passed to the shell. This is the flaw known as ImageTragick and it matters because image processing is often exposed to untrusted files.
Impact
An attacker can execute arbitrary code with the privileges of the process handling the image, leading to full compromise of that process and potentially the host.
Attack surface
Reached by supplying a crafted image to an application that uses ImageMagick for conversion or parsing; the CVSS vector indicates local access with no privileges or user interaction required, though the description frames it as remotely triggerable through crafted images.
Exploitation
Listed in CISA KEV with a 2024-09-30 remediation due date, and EPSS shows a 30-day probability of 0.97485 (99.898th percentile), indicating active exploitation and high likelihood.
What to do
- Upgrade ImageMagick to 6.9.3-10 or 7.0.1-1 or later, or apply the vendor patch referenced in the ChangeLog.
- Apply distribution vendor updates for Ubuntu, Debian, openSUSE, SUSE, Red Hat and Gentoo as applicable.
- Disable or restrict the vulnerable coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT) via policy.xml where full patching is not immediately possible.
- Avoid processing untrusted images with ImageMagick until patched, or sandbox the conversion process with minimal privileges.
Detection
- Monitor for ImageMagick processes spawning shells or unexpected child processes.
- Inspect image files and conversion inputs for shell metacharacters or references to the vulnerable coder formats.
- Review policy.xml configuration to confirm vulnerable coders are disabled or restricted.
- Check for known ImageTragick proof-of-concept payloads in file upload and processing pipelines.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-3714 to the Known Exploited Vulnerabilities catalog on 9 September 2024 as "ImageMagick Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 September 2024.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3714 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3714), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.