---
title: Security advisory 2025-08-28
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

## Magick.NET dependency update to 14.8.1

**CVSS**: 0 (multiple issues with various scores)\
**Affected versions**: 22.0.0 - 30.9.0\
**Category**: Security

### Summary

Xperience by Kentico utilizes the [Magick.NET](https://github.com/dlemstra/Magick.NET) library (**Magick.NET-Q8-AnyCPU** package), which has recently been flagged for multiple vulnerabilities, ranging from **Moderate to High severity**.

As part of our ongoing commitment to platform security, we regularly and automatically update third-party dependencies without explicitly mentioning them in the [changelog](https://docs.kentico.com/changelog.md) or security advisories.

This advisory is issued to provide transparency and reinforce confidence in our proactive approach to dependency management and platform security.

Accordingly, the **Magick.NET-Q8-AnyCPU** package was updated in the following ways:

- To version **14.7.0** in Xperience by Kentico **30.8.0**
- To version **14.8.1** in Xperience by Kentico hotfix **30.9.1**

### How to fix

Update to the latest Xperience by Kentico version. See [Update Xperience by Kentico projects](https://docs.kentico.com/documentation/developers-and-admins/installation/update-xperience-by-kentico-projects.md) for detailed instructions. Optionally, you can temporarily add **Magick.NET-Q8-AnyCPU** version **14.8.1** as a direct package reference to your project.
