THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9hjf-w35w-6vx2 (medium) — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

[GHSA] GHSA-9hjf-w35w-6vx2 (medium) — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

highgithub_advisoriesPublished 2026-09-02

GHSA-9hjf-w35w-6vx2 Severity: medium CVE: CVE-2026-81890

elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

### Summary The PHP connector's CSRF gate protects many mutating commands, but it does not protect the `netmount` connector command. In the shipped minimal connector setup, FTP network mounting is enabled by default, so a cross-site request can force an elF

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9hjf-w35w-6vx2