Skip to content
Threat Feed
high advisory

Argument Injection in ILIAS assImagemapQuestionGUI

An argument injection vulnerability in the ILIAS assImagemapQuestionGUI component allows authenticated question authors to achieve remote code execution by injecting ImageMagick options via crafted filenames.

CVE search metadata

CVE search record: CVE-2026-107639. Severity: high. CVSS: 8.8. KEV: no. Product: ILIAS (< 9.24, 10.x < 10.12, 11.x < 11.5). Brief: Argument Injection in ILIAS assImagemapQuestionGUI. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ilias-arg-injection/

ILIAS, an open-source learning management system, contains an argument injection vulnerability identified as CVE-2026-107639, affecting versions before 9.24, 10.x before 10.12, and 11.x before 11.5. The vulnerability resides within the assImagemapQuestionGUI component, which handles image uploads for question-based assessments. Attackers with permission to author questions can upload image files with specially crafted, tab-separated filenames. Because the application's implementation of escapeshellcmd() fails to neutralize these injected arguments, the underlying ImageMagick convert utility treats the filename segments as functional command-line options. By manipulating these options, an attacker can force the utility to write arbitrary content to a file, such as a PHP shell, within the web-accessible directory. Successful exploitation results in full remote code execution under the privileges of the web server process.

Attack Chain

  1. The attacker authenticates to the ILIAS platform with question authoring privileges.
  2. The attacker creates a new ImageMap question or modifies an existing one.
  3. The attacker prepares a malicious image file where the filename contains tab-separated ImageMagick arguments.
  4. The attacker uploads the crafted file to the assImagemapQuestionGUI interface.
  5. The application passes the malicious filename directly to the ImageMagick convert utility on the host OS.
  6. The convert utility interprets the injected arguments, triggering a file write operation to a location under the web root.
  7. The attacker browses to the newly created, malicious PHP file via the web browser.
  8. The server executes the embedded PHP code, providing the attacker with remote code execution.

Impact

The vulnerability allows an authenticated attacker to execute arbitrary code on the host server. This impact is critical for institutional deployments of ILIAS, as compromised instances may grant attackers access to sensitive student data, grades, and potentially administrative credentials for connected authentication systems. All versions of ILIAS below 9.24, 10.12, and 11.5 are considered vulnerable.

Recommendation

  1. Upgrade all ILIAS instances to version 9.24, 10.12, 11.5, or later immediately to patch CVE-2026-107639.
  2. Audit web server access logs for anomalous requests targeting newly created files or files with unexpected extensions within the ILIAS upload directories.
  3. Restrict question authoring privileges to trusted users until the software has been updated.
  4. Ensure that the ImageMagick convert utility is restricted from performing file-write operations outside of designated temporary directories using security policy configurations.

Immediate actions

Upgrade ILIAS to version 9.24, 10.12, or 11.5

IT Operations 48h

Threat Hunt

Search web logs for suspicious files created in ILIAS upload directories

T1202 medium medium confidence hunt now

Data: webserver access logs

Mitigations

Upgrade ILIAS to 9.24 or later

immediate IT Operations

CVE-2026-107639