Minimagick is a Ruby wrapper library for ImageMagick that enables image processing within web applications and development workflows. Observed vulnerabilities center on OS command injection through improper handling of user-supplied input passed to underlying shell commands, a risk inherent to the library's design as a command-line interface bridge. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minimagick Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13574HIGH In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#o | Jul 12, 2019 | 7.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minimagick Project.
Media articles that mention a CVE ID that affects a product developed by Minimagick Project — matched by CVE ID, not by vendor name.