ImageMagick 7.1.0-49 contains an information disclosure vulnerability when parsing PNG images. If a specially crafted PNG image is processed (for example, during a resize operation), the resulting image may embed the contents of an arbitrary file from the system, provided the magick binary has read permissions for that file. This occurs due to improper handling of file references during image processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository is a small Bash proof-of-concept exploit for CVE-2022-44268, an ImageMagick arbitrary file read vulnerability. It contains two files: a README with setup/usage instructions and one executable script (script.sh) that implements the exploit workflow. The script has two main modes. In '-p' mode, it uses pngcrush to add a PNG text/profile field containing an attacker-controlled filesystem path, producing a crafted image intended to be processed by a vulnerable ImageMagick instance. In '-d' mode, it uses ImageMagick's identify -verbose output, then sed/head/tail/tr and xxd, to extract and decode hex-encoded file contents leaked back into the image metadata. The exploit therefore does not directly attack a remote service itself; instead, it prepares a malicious file and decodes the result after a vulnerable ImageMagick installation has handled that file. Primary capability: arbitrary file read from the system that processes the crafted PNG. Typical target files are local sensitive paths such as /etc/passwd. There is no shell payload, persistence, lateral movement, or network callback logic. The repository is not part of a major exploit framework. Because it includes a working exploit generator and decoder but only a basic hardcoded workflow, the maturity is best classified as OPERATIONAL.
Repository contains a single Python proof-of-concept exploit for CVE-2022-44268 (commonly associated with ImageMagick PNG profile handling leading to arbitrary file read). Structure: (1) README.md with brief HTB-style usage: generate a crafted PNG, upload it to a vulnerable service, download the resulting image, then parse it. (2) poc.py implements two modes via argparse: 'generate' and 'parse'. In 'generate', write() creates a PNG (either based on an existing input PNG or a minimal hardcoded IHDR/IDAT) and injects a PNG tEXt chunk with keyword 'profile' and value set to an attacker-supplied file path (default /etc/passwd). This is the core exploit primitive intended to trigger the vulnerable image-processing backend to read that file and embed its contents into the output image. In 'parse', read() iterates PNG chunks of the returned image and looks for a zTXt chunk. It decompresses the zTXt payload (skipping the first byte after the null separator, consistent with zTXt compression method handling), then parse_data() expects the decompressed content to be hex-encoded bytes (optionally preceded by a line header) and unhexlifies it to recover the stolen file contents. The recovered data can be printed (text or hexdump) or saved to a user-specified output file / extension-based filename. No hardcoded network targets, URLs, or IPs are present; the exploit assumes an external upload/download workflow against a vulnerable service.
This repository provides a proof-of-concept exploit for CVE-2022-44268, a vulnerability in ImageMagick that allows arbitrary file read via crafted PNG images. The main script, 'CVE-2022-44268.py', can both create a poisoned PNG image (embedding a reference to a file to read) and extract file contents from a processed image's metadata. The exploit works by having the attacker craft a PNG image with a reference to a sensitive file (e.g., /etc/hosts), upload it to a server running a vulnerable version of ImageMagick, and then retrieve the processed image to extract the file's contents. The repository includes a Dockerfile for easy setup, a requirements.txt for dependencies, and a README.md with usage instructions and example endpoints. The attack vector is network-based, requiring the ability to upload and retrieve images from the target server. The exploit is a proof-of-concept and does not include weaponized or automated payload delivery.
This repository provides a Python exploit script (cve-2022-44268.py) that automates exploitation of CVE-2022-44268, a vulnerability in ImageMagick allowing arbitrary file read via crafted PNG images. The script takes a base PNG, a list of target file paths (from filelist.lst, filelist2.lst, or filelist3.lst), a Burp Suite request file for a vulnerable image upload endpoint, and output directories. For each file path, it crafts a malicious PNG embedding the file path in a 'profile' text chunk, uploads it to the target server using the provided HTTP request, downloads the processed image, and extracts the file content from the image metadata using ImageMagick's 'identify' tool. The extracted files are saved locally. The exploit is operational and requires the attacker to have access to a vulnerable file upload endpoint and a valid upload request. The repository is structured with one main exploit script, three file lists of target files, and a README with usage instructions.
This repository automates the exploitation of CVE-2022-44268, a file disclosure vulnerability in ImageMagick. It contains two files: a README.md with detailed setup and usage instructions, and exploit.py, a Python script that orchestrates the attack. The script requires the VoidZone Rust PoC to generate a malicious PNG file containing the contents of a specified file (e.g., /etc/passwd). The script uploads this PNG to a target web application's image upload endpoint, retrieves the processed image, and uses exiftool to extract and print the exfiltrated file content. The exploit is operational and requires the attacker to configure the target URL, payload path, and optionally proxy settings. The main attack vector is network-based, targeting web applications that process user-uploaded images with a vulnerable version of ImageMagick. The script is not a detection tool but a full exploit, capable of exfiltrating arbitrary files from the server if the vulnerability is present.
This repository is a proof-of-concept exploit for CVE-2022-44268, a vulnerability in ImageMagick that allows arbitrary file read via crafted PNG images. The structure includes Rust code (src/main.rs) to generate a PNG image with a user-supplied file path embedded in a text chunk, a Python script (script.py) to automate the upload of this image to a target web application (http://pilgrimage.htb/), and a Bash script (main.sh) to orchestrate the process and decode the result. The exploit works by uploading the crafted image to a vulnerable ImageMagick instance, which, when processing the image, embeds the contents of the specified file into the output. The script then downloads and decodes the output to retrieve the file contents. The repository is tailored for the pilgrimage.htb HackTheBox challenge but demonstrates a general technique for exploiting this vulnerability. No fake or detection-only scripts are present; the code is a functional exploit.
This repository provides a Bash script (script.sh) that exploits the ImageMagick CVE-2022-44268 arbitrary file read vulnerability. The exploit works by embedding the contents of a specified file from the target system into a PNG image's text profile using pngcrush. The script offers two main modes: '-p' to prepare a malicious PNG by embedding the file, and '-d' to extract and decode the embedded file contents from a PNG. The README provides setup instructions, usage examples, and references to original research. The exploit targets ImageMagick version 6.9.11-60 on Linux systems and requires the attacker to know the path of the file to be read. The repository consists of a single exploit script and a README, with no network endpoints or remote attack vectors; the attack is performed locally or in environments where the attacker can supply images to a vulnerable ImageMagick instance.
This repository provides a proof-of-concept exploit for CVE-2022-44268, a vulnerability in ImageMagick that allows arbitrary file read via crafted PNG images. The main script, CVE-2022-44268.py, can operate in two modes: (1) it can poison a PNG image by embedding a reference to a file to be read from the server, and (2) it can extract and decode the contents of a file from a PNG image that has been processed by a vulnerable ImageMagick instance. The exploit requires the attacker to upload a crafted PNG to a vulnerable server and then retrieve the processed image to extract the file contents. The repository includes a Dockerfile for easy setup, a requirements.txt for dependencies, and a README.md with detailed usage instructions and example endpoints. The exploit is a proof-of-concept and does not include weaponized payloads or automation for exploitation at scale.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2022-44268, an information disclosure vulnerability in ImageMagick 7.1.0-49. The repository contains two files: a README.md with detailed usage instructions and background, and generate.py, a Python script that creates a malicious PNG file. The script generates a blank PNG image, embeds a reference to a local file (such as /etc/passwd) in the PNG's profile metadata, and outputs the crafted image. When this image is processed by a vulnerable ImageMagick installation, the contents of the specified file are embedded in the output image's metadata, which can then be extracted by the attacker. The exploit demonstrates the ability to read arbitrary files from the target system, provided the attacker can supply a PNG file to be processed by ImageMagick. The code is straightforward, does not use any exploit frameworks, and is intended as a PoC for research and demonstration purposes.
This repository provides a proof-of-concept exploit for CVE-2022-44268, a vulnerability in ImageMagick (v7.1.0-49) that allows attackers to exfiltrate arbitrary files from a server. The exploit consists of a single Python script (CVE-2022-44268.py) that takes a file path as an argument and embeds it into a PNG file as a tEXt chunk with the keyword 'Profile'. When this crafted PNG is processed by ImageMagick (e.g., during a resize operation), the contents of the specified file are embedded into the output image. The README.md provides detailed usage instructions and background on the vulnerability. The repository is structured simply, with the main exploit script, a README, and a license file. No network endpoints are present; the attack vector is local file inclusion via image processing.
This repository contains a proof-of-concept exploit for ImageMagick CVE-2022-44268, which is an information disclosure vulnerability. The main file, poc.py, is a Python script that can generate a PNG image with an embedded file (default: /etc/passwd) in a tEXt chunk, or parse such a PNG to extract the embedded file contents. The exploit demonstrates how an attacker can use a crafted PNG to exfiltrate arbitrary files from a system where ImageMagick processes untrusted images. The repository consists of a README and the exploit script, with the latter being the entry point. No network endpoints are present; the attack vector is local file processing by a vulnerable application.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.