Breaking
CVE-2026-63223critical

CVE-2026-63223: Critical CodeIgniter File Upload Flaw Found

A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.

9.8/10 CVSS
Vendor / Productcomposer/codeigniter4/framework
Affected Versionscomposer/codeigniter4/framework (prior to 4.7.4)
Fixed In4.7.4
Advertisement

What This Means

Advisory ID: GHSA-mmj4-63m4-r6h5 (CVE-2026-63223)
Summary: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Severity: critical (CVSS 9.8)
Affected packages: composer/codeigniter4/framework (patched in 4.7.4)
Details: ### Impact
This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they:
- validate uploads using `is_image` or `mime_in` without an independent safe extension check, such as `ext_in` on patched versions
- save uploaded files using the client-supplied filename
- place uploads in a web-accessible directory where PHP files can execute

### Patches
Upgrade to v4.7.4 or later.

### Workarounds
- Save uploads outside the public web root, preferably under `writable/uploads`.
- Use `$file->store()` or `$file->move($path, $file->getRandomName())` instead of preserving the original client filename.
- Disable script execution in any public upload directory.
- Manually verify the client filename extension before moving the file.
- For image uploads, reject files when `$file->getClientExtension()` is not an allowed image extension.
- For exact MIME-type validation, reject files when `$file->getClientExtension()` does not match `$file->guessExtension()`.

How to Fix It

  • Upgrade to CodeIgniter 4.7.4 or later
  • Save uploads outside the public web root
  • Use getRandomName() instead of preserving client-supplied filenames
  • Disable script execution in public upload directories
  • Manually verify file extensions before processing uploads

Source

GitHub Security Advisories

Read our full coverage of CVE-2026-63223 →

Last updated August 7, 2026 UTC