studio-42/elfinder Security Advisories for 2.1.69 (3)
-
[HIGH] elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
PKSA-71vn-d2sp-v1x4 CVE-2026-81891 GHSA-gxmj-r5rf-ggwq
Affected version: <2.1.70
Reported by:
GitHub -
[MEDIUM] elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
PKSA-th2b-2jzf-hmp6 CVE-2026-81890 GHSA-9hjf-w35w-6vx2
Affected version: <2.1.70
Reported by:
GitHub -
[HIGH] elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
PKSA-r7xr-47v5-58tx CVE-2026-81889 GHSA-8x3q-jpjh-qh5c
Affected version: <=2.1.69
Reported by:
GitHub