PKSA-71vn-d2sp-v1x4 Security Advisory
-
[HIGH] elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
PKSA-71vn-d2sp-v1x4 CVE-2026-81891 GHSA-gxmj-r5rf-ggwq
Affected package: studio-42/elfinder
Affected version: <2.1.70
Reported by:
GitHub