MODX AjaxUpload Extra Remote Execution and Others

Security Advisory: AjaxUpload Extra

Overview

  • Project: AjaxUpload Extra
  • CVE IDs: CVE-2026-95237 (pending publication); three further IDs to be assigned
  • Affected Versions: 2.0.0 through 2.0.6
  • Fixed Version: 2.1.0
  • Release Date: 2026-10-05
  • Severity: Critical
  • Highest CVSS v3.1 Score: 9.8

Summary

Four security vulnerabilities have been fixed in AjaxUpload 2.1.0. Two allow a remote visitor to run code on the server without logging in. All four are fixed by the same update.

Vulnerability Details

# Type Severity CVSS v3.1 Vector CVE ID
1 Remote Code Execution (unrestricted file upload) Critical 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-95237 (pending)
2 Remote Code Execution (insufficient input validation) Critical 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H To be assigned
3 Server-Side Request Forgery (SSRF) High 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N To be assigned
4 Arbitrary file deletion (path traversal) High 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H To be assigned

Description

Insufficient validation of user-supplied input in AjaxUpload allows an unauthenticated remote visitor to upload executable files, cause the server to send requests to addresses of the visitor’s choosing, or delete files on the server. Depending on the site, these issues can lead to full compromise of the web server account.

Affected Systems

All MODX Revolution installations with AjaxUpload 2.0.6 or earlier installed. Not every issue applies to every configuration, but at least one applies to every installation. Treat every installation as affected until it is upgraded.

Mitigation

Update immediately: Upgrade AjaxUpload to version 2.1.0 or later using the MODX Extras Installer.

If you cannot upgrade right away, uninstall AjaxUpload until you can.

Upgrading does not remove files an attacker may already have placed on your server. After upgrading:

  • Check for unexpected files, particularly PHP files, in AjaxUpload’s cache directory and in any directory your forms upload to.
  • Review web server logs for unusual requests to the AjaxUpload component.
  • If you find anything suspicious, treat the site as compromised and rotate your database credentials.

Credits

  • Discovery: Sosecure; Grim The Ripper Team by SOSECURE Thailand; Mr. Warathap Ratsameekomon
  • Resolution: Thomas Jakobi
  • Coordination: MODX Security Team

Timeline

  • Discovery Date: 2026-09-18
  • Fix Development: 2026-10-01
  • Public Disclosure: 2026-10-05

References

Revision History

  • 2026-10-05: Initial advisory publication