
Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-45140
Chamilo LMS 2.0.0 - chamilo
I am @abraxas_null. Loopback lab. The client is CVE-2026-45140-Abraxas-Labs.py.
The advisory did not name the file. Unauthenticated RCE via leftover CStudio big-upload.php. key is concatenated onto cacheDir/cstudio_upload/ with no sanitization. action=upload appends php://input there. Traverse into public/. 2.0.0 has no api_get_user_id() on that script. Patched in 2.0.1 (403 + disable_dangerous_file).
| CVE | CVE-2026-45140 · CVE.org |
| CWE | CWE-22, CWE-94, CWE-219, CWE-434 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | Chamilo LMS |
| Affected | all versions through 2.0.0 (inclusive) |
| Patched | 2.0.1 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
POST the plugin path with action=upload and a key that walks into public/. Body is attacker bytes. GET the written file. Writing .php under public/ is RCE. The lab witness is .txt because fopen appends and a second <?php in the same file is a parse error.
The GHSA named RCE and not the path. I grepped CStudio for uploads, then read setTempName and uploadFile. This is not a Symfony action=. It is a leftover chunked-upload script under public/plugin.
POST, then GET. {"key":"...poc-witness.txt","errorStatus":0} is the router matching. Then GET /poc-witness.txt.
Wrong turns: hitting a Symfony route; 302 to /main/install/index.php because APP_INSTALLED is not 1; 403 JSON Forbidden on 2.0.1; GET without action=upload; writing .php twice and calling the parse error a miss.
Port 8088. Chamilo LMS 2.0.0 installed (APP_INSTALLED=1). CStudio plugin files under public/plugin/CStudio.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-45140-Abraxas-Labs.py
Witness: GET /poc-witness.txt contains POCWitness45140. Installer HTML or 403 JSON is not it.
Ways to lose without learning anything:
Update Chamilo LMS to 2.0.1 or newer. Re-run CVE-2026-45140-Abraxas-Labs.py against the patched build: POCWitness45140 must not appear.
github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844
github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m
github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45140.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.