THREAT OPS › Threat News › [GHSA] GHSA-gxmj-r5rf-ggwq (high) — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
[GHSA] GHSA-gxmj-r5rf-ggwq (high) — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
GHSA-gxmj-r5rf-ggwq Severity: high CVE: CVE-2026-81891
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
### Summary
elFinder provides `uploadDeny` and `uploadAllow` options in its connector configuration to restrict which MIME types may be uploaded. When `uploadDeny` includes `text/x-php`, direct upload of `.php`, `.phtml`, and `.phar` files is correctly b
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-81891cve
Original source: https://github.com/advisories/GHSA-gxmj-r5rf-ggwq