← Vulnerability feed

Vulnerability record · CVE-2026-41247 · published 23 April 2026

CVE-2026-41247: Std42 elfinder os command injection vulnerability

Std42 · Elfinder

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that use the ImageMagick CLI backend, this value is incorporated into shell command strings without sufficient escaping. An attacker able to invoke the resize command with a crafted bg value may achieve arbitrary command execution as the web server process user. This vulnerability is fixed in 2.1.67.

8.9 CVSS 4.0 High EPSS 2.7% · top 14.9% CWE-78 · OS command injection
8.9CVSS 4.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that use the ImageMagick CLI backend, this value is incorporated into shell command strings without sufficient escaping. An attacker able to invoke the resize command with a crafted bg value may achieve arbitrary command execution as the web server process user. This vulnerability is fixed in 2.1.67.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41247 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-52044Std42 elfinder unrestricted file upload vulnerabilityStudio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.EPSS 0.79%9.8CVE-2024-38909Std42 elfinder improper access control vulnerabilityStudio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a…EPSS 0.48%9.8CVE-2022-27115Std42 elfinder unrestricted file upload vulnerabilityIn Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.EPSS 29%9.8CVE-2021-43421Std42 elfinder unrestricted file upload vulnerabilityA File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar…EPSS 43%9.8CVE-2021-32682elFinder PHP connector path traversal, command injection and SSRFSeveral vulnerabilities in elFinder 2.1.58 affect the PHP connector, combining path traversal, OS command injection and server-side request forgery. …EPSS 70%analysed9.8CVE-2021-23394Std42 elfinder unrestricted file upload vulnerabilityThe package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only…EPSS 19%9.8CVE-2019-9194elFinder PHP connector command injection before 2.1.48elFinder before 2.1.48 contains an OS command injection flaw in its PHP connector (CWE-78). The vulnerability is remotely reachable without authentic…EPSS 97%analysed9.1CVE-2022-26960elFinder path traversal in connector.minimal.php allows file access outside rootconnector.minimal.php in std42 elFinder through 2.1.60 mishandles absolute file paths, enabling path traversal. Unauthenticated remote attackers can …EPSS 51%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41247), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.