CVE-2022-44268
MEDIUM 6.5EPSS 89.9%
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS
- 89.85% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2023-02-06
- Updated
- 2025-03-26
Proof-of-concept exploits (32)
- Ashifcoder/CVE-2022-44268-automated-poc0★ · 2023-02-04
- Baikuya/CVE-2022-44268-PoC2★ · 2023-02-04
- BhattJayD/PilgrimageCtfExploit0★ · 2024-01-01
- CygnusX-26/CVE-2022-44268-fixed-PoC0★ · 2023-12-04
- FlojBoj/CVE-2022-442680★ · 2024-09-02
- J0ey17/Automate_Exploit_CVE-2022-442680★ · 2025-06-04
- LGenAgul/ImageMagick-7.1.0.-49-exploit0★ · 2024-08-20
- NataliSemi/-CVE-2022-442680★ · 2023-11-16
- Pog-Frog/cve-2022-442680★ · 2023-07-14
- Vagebondcur/IMAGE-MAGICK-CVE-2022-442680★ · 2023-10-13
- Vulnmachines/imagemagick-CVE-2022-442688★ · 2023-02-06
- adhikara13/CVE-2022-44268-MagiLeak2★ · 2023-06-26
- agathanon/cve-2022-442684★ · 2023-02-03
- atici/Exploit-for-ImageMagick-CVE-2022-442680★ · 2026-07-31
- backglass/readermagick0★ · 2024-02-18
- betillogalvanfbc/POC-CVE-2022-442681★ · 2023-03-22
- bhavikmalhotra/CVE-2022-44268-Exploit1★ · 2023-07-02
- chairat095/CVE-2022-44268_By_Kyokito2★ · 2023-08-13
- duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC275★ · 2023-02-02
- entr0pie/CVE-2022-4426813★ · 2023-07-03
- fanbyprinciple/ImageMagick-lfi-poc1★ · 2023-07-24
- jkobierczynski/cve-2022-442680★ · 2025-08-05
- katseyres2/CVE-2022-44268-pilgrimage0★ · 2025-05-02
- kljunowsky/CVE-2022-4426827★ · 2023-12-29
- mouftan/CVE-2022-442680★ · 2025-07-31
- narekkay/auto-cve-2022-44268.sh2★ · 2023-07-18
- nfm/heroku-CVE-2022-44268-reproduction0★ · 2023-02-21
- voidz0r/CVE-2022-44268219★ · 2025-03-24
- y1nglamore/CVE-2022-44268-ImageMagick-Vulnerable-Docker-Environment10★ · 2023-02-03
- atici/ImageMagick-CVE-2022-44268-PoC
- jnschaeffer/cve-2022-44268-detector
- k-javaman12/CVE-2022-44268-