Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2025-32460: GraphicsMagick could let attackers execute code

CVE-2025-32460 · published 1 day ago
Summary

The GraphicsMagick program included in Root's Alpine 3.24 Linux distribution had a flaw that could let a malicious user run unwanted code on the server. This risk has been corrected in newer releases of the package. Install the latest GraphicsMagick update for Root to keep the system safe.

What to do
  • Update graphicsmagick to version 1.3.45-r00074.
  • Update rootio-graphicsmagick to version 1.3.45-r00074.
  • Update graphicsmagick to version 1.3.45-r00075.
  • Update rootio-graphicsmagick to version 1.3.45-r00075.
  • Update graphicsmagick to version 1.3.47-r00071.
  • Update rootio-graphicsmagick to version 1.3.47-r00071.
  • Update graphicsmagick graphicsmagick to version 1.3.46 or later.
Affected software
Ecosystem VendorProductAffected versions
– graphicsmagick graphicsmagick < 1.3.46
cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*
Root:Alpine:3.22 – graphicsmagick < 1.3.45-r00074
< 1.3.45-r00075
Fix: upgrade to 1.3.45-r00074
Root:Alpine:3.22 – rootio-graphicsmagick < 1.3.45-r00074
< 1.3.45-r00075
Fix: upgrade to 1.3.45-r00074
Root:Alpine:3.24 – graphicsmagick < 1.3.47-r00071
Fix: upgrade to 1.3.47-r00071
Root:Alpine:3.24 – rootio-graphicsmagick < 1.3.47-r00071
Fix: upgrade to 1.3.47-r00071
Original advisory text
CVE-2025-32460 in graphicsmagick - Patched by Root
Root has patched CVE-2025-32460 in the graphicsmagick package for Root:Alpine:3.24. Multiple fixed versions available.
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-125Out-of-bounds Read
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen7 Mar 2026
Track software like this
Free during beta