CVE-2026-81890: Elfinder Missing Netmount Csrf Protection

The 'netmount' command is omitted from $csrfProtectedCmds in elFinderConnector, allowing cross-site requests to perform network mount operations without CSRF token validation (CVE-2026-81890).

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-81890-elfinder-missing-netmount-csrf-protection --engine opengrep

Description

The 'netmount' command is omitted from $csrfProtectedCmds in elFinderConnector, allowing cross-site requests to perform network mount operations without CSRF token validation (CVE-2026-81890).