CVE-2026-63223critical
CVE-2026-63223: Critical CodeIgniter File Upload Flaw Found
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
9.8/10 CVSS
Vendor / Productcomposer/codeigniter4/framework
Affected Versionscomposer/codeigniter4/framework (prior to 4.7.4)
Fixed In4.7.4
Advertisement
What This Means
Advisory ID: GHSA-mmj4-63m4-r6h5 (CVE-2026-63223) Summary: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules Severity: critical (CVSS 9.8) Affected packages: composer/codeigniter4/framework (patched in 4.7.4) Details: ### Impact This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations. Applications are impacted when they: - validate uploads using `is_image` or `mime_in` without an independent safe extension check, such as `ext_in` on patched versions - save uploaded files using the client-supplied filename - place uploads in a web-accessible directory where PHP files can execute ### Patches Upgrade to v4.7.4 or later. ### Workarounds - Save uploads outside the public web root, preferably under `writable/uploads`. - Use `$file->store()` or `$file->move($path, $file->getRandomName())` instead of preserving the original client filename. - Disable script execution in any public upload directory. - Manually verify the client filename extension before moving the file. - For image uploads, reject files when `$file->getClientExtension()` is not an allowed image extension. - For exact MIME-type validation, reject files when `$file->getClientExtension()` does not match `$file->guessExtension()`.
How to Fix It
- Upgrade to CodeIgniter 4.7.4 or later
- Save uploads outside the public web root
- Use getRandomName() instead of preserving client-supplied filenames
- Disable script execution in public upload directories
- Manually verify file extensions before processing uploads
Source
Last updated August 7, 2026 UTC