THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gxmj-r5rf-ggwq (high) — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

[GHSA] GHSA-gxmj-r5rf-ggwq (high) — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

medgithub_advisoriesPublished 2026-09-02

GHSA-gxmj-r5rf-ggwq Severity: high CVE: CVE-2026-81891

elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

### Summary

elFinder provides `uploadDeny` and `uploadAllow` options in its connector configuration to restrict which MIME types may be uploaded. When `uploadDeny` includes `text/x-php`, direct upload of `.php`, `.phtml`, and `.phar` files is correctly b

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gxmj-r5rf-ggwq