---
id: CVE-2026-107639
title: >-
  ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument
  injection vulnerability in assImagemapQuestionGUI that allows question authors
  to inject ImageMagick convert options via uploaded image filenames
summary: >-
  ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument
  injection vulnerability in assImagemapQuestionGUI that allows question authors
  to inject ImageMagick convert options via uploaded image filenames. Attackers
  c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-88
vendor: ILIAS-eLearning e.V.
product: ILIAS
affected:
  - ILIAS >= 9.0 < 9.24
  - ILIAS >= 10.0 < 10.12
  - ILIAS >= 11.0 < 11.5
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:17:47.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107639'
references:
  - url: 'https://docu.ilias.de/go/blog/15821/950'
    label: disclosure@vulncheck.com
  - url: 'https://docu.ilias.de/go/blog/15821/951'
    label: disclosure@vulncheck.com
  - url: 'https://docu.ilias.de/go/blog/15821/952'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ILIAS-eLearning/ILIAS'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestion.php#L290-L306
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestionGUI.php#L130
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.ilImagemapPreview.php#L208-L238
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ILIAS-eLearning/ILIAS/commit/ad1423c365a7ffd25bac711d995c643ce2af65c6
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ilias-before-9.24-10.12-and-11.5-argument-injection-via-image-map-question-upload-filename
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T14:47:16.353Z'
---

## Overview

ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
