GHSA-mmj4-63m4-r6h5
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Quick fix
GHSA-mmj4-63m4-r6h5 — codeigniter4/framework: upgrade to the fixed version with the command below.
composer require codeigniter4/framework:^4.7.4 Details
### Impact This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.
Applications are impacted when they: - validate uploads using `is_image` or `mime_in` without an independent safe extension check, such as `ext_in` on patched versions - save uploaded files using the client-supplied filename - place uploads in a web-accessible directory where PHP files can execute
### Patches Upgrade to v4.7.4 or later.
### Workarounds - Save uploads outside the public web root, preferably under `writable/uploads`. - Use `$file->store()` or `$file->move($path, $file->getRandomName())` instead of preserving the original client filename. - Disable script execution in any public upload directory. - Manually verify the client filename extension before moving the file. - For image uploads, reject files when `$file->getClientExtension()` is not an allowed image extension. - For exact MIME-type validation, reject files when `$file->getClientExtension()` does not match `$file->guessExtension()`.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 4.7.4 composer require codeigniter4/framework:^4.7.4 References
- https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-mmj4-63m4-r6h5 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-63223 [ADVISORY]
- https://github.com/codeigniter4/CodeIgniter4/commit/b6e9a4fa1dca2df3d3f261bdf61532df8c6420aa [WEB]
- https://github.com/codeigniter4/CodeIgniter4 [PACKAGE]
- https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4 [WEB]