ImagePanick: From SVG to RCE Chaining Weak Policies and Bugs in ImageMagick and Ghostscript
How a single SVG file can achieve arbitrary file write (and RCE) by chaining weak default policies in ImageMagick with vulnerabilities in Ghostscript 10.06.0, completely bypassing GS SAFER mode.