THREAT OPS › Threat News › [GHSA] GHSA-9hjf-w35w-6vx2 (medium) — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
[GHSA] GHSA-9hjf-w35w-6vx2 (medium) — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
GHSA-9hjf-w35w-6vx2 Severity: medium CVE: CVE-2026-81890
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
### Summary The PHP connector's CSRF gate protects many mutating commands, but it does not protect the `netmount` connector command. In the shipped minimal connector setup, FTP network mounting is enabled by default, so a cross-site request can force an elF
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- ec5f811dc321a053085b994966f553eaaab58721sha1
- CVE-2026-81890cve
- http://127.0.0.1:8765/connector.phpurl
Original source: https://github.com/advisories/GHSA-9hjf-w35w-6vx2