Argument Injection in ILIAS assImagemapQuestionGUI
An argument injection vulnerability in the ILIAS assImagemapQuestionGUI component allows authenticated question authors to achieve remote code execution by injecting ImageMagick options via crafted filenames.
CVE search metadata
CVE search record: CVE-2026-107639. Severity: high. CVSS: 8.8. KEV: no. Product: ILIAS (< 9.24, 10.x < 10.12, 11.x < 11.5). Brief: Argument Injection in ILIAS assImagemapQuestionGUI. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/
ILIAS, an open-source learning management system, contains an argument injection vulnerability identified as CVE-2026-107639, affecting versions before 9.24, 10.x before 10.12, and 11.x before 11.5. The vulnerability resides within the assImagemapQuestionGUI component, which handles image uploads for question-based assessments. Attackers with permission to author questions can upload image files with specially crafted, tab-separated filenames. Because the application's implementation of escapeshellcmd() fails to neutralize these injected arguments, the underlying ImageMagick convert utility treats the filename segments as functional command-line options. By manipulating these options, an attacker can force the utility to write arbitrary content to a file, such as a PHP shell, within the web-accessible directory. Successful exploitation results in full remote code execution under the privileges of the web server process.
Attack Chain
- The attacker authenticates to the ILIAS platform with question authoring privileges.
- The attacker creates a new ImageMap question or modifies an existing one.
- The attacker prepares a malicious image file where the filename contains tab-separated ImageMagick arguments.
- The attacker uploads the crafted file to the
assImagemapQuestionGUIinterface. - The application passes the malicious filename directly to the ImageMagick
convertutility on the host OS. - The
convertutility interprets the injected arguments, triggering a file write operation to a location under the web root. - The attacker browses to the newly created, malicious PHP file via the web browser.
- The server executes the embedded PHP code, providing the attacker with remote code execution.
Impact
The vulnerability allows an authenticated attacker to execute arbitrary code on the host server. This impact is critical for institutional deployments of ILIAS, as compromised instances may grant attackers access to sensitive student data, grades, and potentially administrative credentials for connected authentication systems. All versions of ILIAS below 9.24, 10.12, and 11.5 are considered vulnerable.
Recommendation
- Upgrade all ILIAS instances to version 9.24, 10.12, 11.5, or later immediately to patch CVE-2026-107639.
- Audit web server access logs for anomalous requests targeting newly created files or files with unexpected extensions within the ILIAS upload directories.
- Restrict question authoring privileges to trusted users until the software has been updated.
- Ensure that the ImageMagick
convertutility is restricted from performing file-write operations outside of designated temporary directories using security policy configurations.
Immediate actions
Upgrade ILIAS to version 9.24, 10.12, or 11.5
Threat Hunt
Search web logs for suspicious files created in ILIAS upload directories
Data: webserver access logs
Mitigations
Upgrade ILIAS to 9.24 or later
CVE-2026-107639