PT-2026-34727 · Elfinder+1 · Elfinder+1

Mcdruid

·

Published

2026-04-17

·

Updated

2026-04-23

·

CVE-2026-41247

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions elFinder versions prior to 2.1.67
Description An issue exists in the resize command where the bg (background color) parameter is accepted from user input and passed through image resize or rotate processing. In configurations utilizing the ImageMagick CLI backend, this value is incorporated into shell command strings without sufficient escaping, allowing an attacker to achieve arbitrary command execution as the web server process user.
Recommendations Update to version 2.1.67.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-41247
GHSA-8Q4H-8CRM-5CVC

Affected Products

Imagemagick
Elfinder