VDB
KO
CRITICAL 9.4

GHSA-c9w5-rwh3-7pm9

CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

Quick fix

GHSA-c9w5-rwh3-7pm9 — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^4.7.4

Details

### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQL **with their escape flag ignored**, so they are never escaped or quoted. If an application passes user-controlled input to `where()` before calling `deleteBatch()`, that input is interpreted as SQL rather than as a value, allowing SQL injection.

This affects only the `deleteBatch()` code path. Regular `delete()` operations escape `where()` binds correctly.

### Patches Upgrade to v4.7.4 or later.

### Workarounds If you cannot upgrade immediately:

- Strictly validate and cast values (e.g. numeric IDs) before using them in conditions - though this does not fully protect string conditions. - Do not pass user-controlled input to `where()` when using `deleteBatch()`. - For user-controlled conditions, use a normal `delete()` with Query Builder binds instead of `deleteBatch(`). - Where possible, express required matching values through the batch data and `onConstraint()` rather than as separate user-controlled `where()` clauses.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / codeigniter4/framework
Introduced in: 4.3.0 Fixed in: 4.7.4
Fix composer require codeigniter4/framework:^4.7.4

References