elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that use the ImageMagick CLI backend, this value is incorporated into shell command strings without sufficient escaping. An attacker able to invoke the resize command with a crafted bg value may achieve arbitrary command execution as the web server process user. This vulnerability is fixed in 2.1.67.
References
| Link | Resource |
|---|---|
| https://github.com/Studio-42/elFinder/security/advisories/GHSA-8q4h-8crm-5cvc | Mitigation Vendor Advisory |
Configurations
History
28 Apr 2026, 18:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Std42 elfinder
Std42 |
|
| CPE | cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/Studio-42/elFinder/security/advisories/GHSA-8q4h-8crm-5cvc - Mitigation, Vendor Advisory |
23 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 19:17
Updated : 2026-04-28 18:57
NVD link : CVE-2026-41247
Mitre link : CVE-2026-41247
CVE.ORG link : CVE-2026-41247
JSON object : View
Products Affected
std42
- elfinder
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
