ImageTragick (CVE-2016-3714) is an OS command injection vulnerability in ImageMagick versions before 6.9.3-10 and 7.x before 7.0.1-1. The EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders can improperly handle shell metacharacters embedded in a crafted image. When a vulnerable ImageMagick installation processes such an image, attacker-controlled shell syntax can result in arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'ImageMagick Delegate Arbitrary Command Execution' (modules/exploits/unix/fileformat/imagemagick_delegate.rb). The module exploits command injection vulnerabilities in the way ImageMagick processes 'delegate' commands for file conversions, affecting versions <= 7.0.1-0 and <= 6.9.3-9 (legacy). The exploit works by generating a malicious image file (SVG, MVG, or PS) that, when processed by a vulnerable ImageMagick installation, executes arbitrary shell commands supplied by the attacker. The module supports multiple file formats and vectors, including a popen() vector and a Ghostscript delegate bypass. The payload is customizable via the Metasploit framework and is encoded to avoid problematic characters. The only notable file path in the code is '/dev/tty', used as a placeholder in the template mechanism. The module references CVE-2016-3714 and CVE-2016-7976, and is weaponized for operational use within Metasploit. The repository is structured as a typical Metasploit exploit module, with all logic contained in a single Ruby file.
This repository provides a comprehensive exploit toolkit for CVE-2016-3714 (ImageMagick 'ImageTragick'). It contains two main exploit components: 1. 'imagick_builder.py' is a Python script that interactively generates malicious image files (MVG, SVG) designed to exploit vulnerable ImageMagick installations. It supports payloads for remote code execution, file read, file move, file delete, and SSRF. The script allows the user to specify commands, file paths, or URLs to embed in the payloads, and outputs the crafted images to an 'output/' directory. 2. 'imagick_bypass_shell.php' is a PHP web shell that leverages the Imagick extension to bypass PHP's disabled functions and execute system commands, read arbitrary files, or delete files on the server. It provides a web interface where attackers can supply parameters (cmd, read, del) to perform these actions. The shell works by generating and processing malicious image payloads on the fly using Imagick. The repository also includes a 'classes/colors.py' module for colored terminal output in the Python script, and a README.md with usage instructions and screenshots. The main attack vectors are network-based (uploading or processing malicious images via web applications) and local (abusing the Imagick extension on the server). Several fingerprintable endpoints are present, including example file paths and web shell URLs. The exploit is operational and provides both payload generation and a ready-to-use web shell for post-exploitation.
This repository provides a set of proof-of-concept (POC) exploits for CVE-2016-3714 (ImageTragick), targeting vulnerable ImageMagick installations. The exploit leverages the ability to embed shell commands within MVG and SVG image files, which are then executed by the server when processed by ImageMagick. The repository contains multiple payloads in different scripting languages (bash, nc, perl, php, python), each designed to establish a reverse shell or execute arbitrary commands on the target server. The structure is organized by payload type and includes both direct reverse shell payloads and command execution tests (e.g., using curl, wget, ping, telnet, nslookup). The README provides usage instructions, indicating that the attacker should set up a listener (e.g., with netcat) and upload the crafted image files to a vulnerable server. The endpoints used in the payloads are primarily localhost (127.0.0.1) for demonstration, but one payload targets an external IP (114.34.41.13). The repository is a comprehensive demonstration of the ImageTragick vulnerability and its exploitation via malicious image uploads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The historical ImageMagick delegate command injection vulnerability referenced for comparison as the same bug class, not the main subject of the article.
The well-known ImageMagick command execution vulnerability referenced as historical context for similar image-processing delegate abuse.
A delegate command injection vulnerability in ImageMagick, commonly known as ImageTragick.
A prior ImageMagick remote code execution vulnerability, known as ImageTragick, referenced as historical context for security risks in ImageMagick coders.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.