CVE-2016-3714
KEVHIGH 10.0EPSS 97.5%
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
- CVSS v3.1
- 8.4 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.4 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 97.48% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-09-09
- Published
- 2016-05-05
- Updated
- 2025-10-21
Proof-of-concept exploits (13)
- http://www.rapid7.com/db/modules/exploit/unix/fileformat/imagemagick_delegate
- Hood3dRob1n/CVE-2016-371470★ · 2016-05-07
- JoshMorrison99/CVE-2016-37141★ · 2022-12-02
- Macr0phag3/Exp-or-Poc6★ · 2021-01-16
- MrrRaph/pandagik1★ · 2022-04-26
- PandH4cker/pandagik1★ · 2022-04-26
- SgtMate/container_escape_showcase1★ · 2024-05-03
- jpeanut/ImageTragick-CVE-2016-3714-RShell18★ · 2016-05-29
- mmomtchev/magickwand.js94★ · 2026-06-30
- sardine-web/File-Upload1★ · 2025-06-25
- shelld3v/RCE-python-oneliner-payload32★ · 2021-09-09
- snyk-labs/container-breaking-in-goof8★ · 2026-06-17
- tommiionfire/CVE-2016-37140★ · 2016-05-04