elFinder Command Injection Vulnerability in Resize Background Parameter Allowing Arbitrary Command Execution

Vulnerability

A command injection vulnerability has been identified in elFinder versions prior to 2.1.67. The issue arises in the 'resize' command, where the 'bg' (background color) parameter is accepted from user input and passed through image processing with the ImageMagick CLI backend. This parameter is incorporated into shell command strings without adequate escaping, allowing an attacker to inject shell metacharacters and execute arbitrary commands as the web server process user.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server, with the same privileges as the web server process.

Remediation

Users are advised to upgrade to elFinder version 2.1.67 or later. For those unable to upgrade immediately, the 'resize' command can be disabled, the ImageMagick CLI backend can be avoided for image processing, and access can be restricted to trusted users only.

Added: Apr 23, 2026, 7:38 PM
Updated: Apr 23, 2026, 7:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
6.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.