GHSA-c9w5-rwh3-7pm9
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
Quick fix
GHSA-c9w5-rwh3-7pm9 — codeigniter4/framework: upgrade to the fixed version with the command below.
composer require codeigniter4/framework:^4.7.4 Details
### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQL **with their escape flag ignored**, so they are never escaped or quoted. If an application passes user-controlled input to `where()` before calling `deleteBatch()`, that input is interpreted as SQL rather than as a value, allowing SQL injection.
This affects only the `deleteBatch()` code path. Regular `delete()` operations escape `where()` binds correctly.
### Patches Upgrade to v4.7.4 or later.
### Workarounds If you cannot upgrade immediately:
- Strictly validate and cast values (e.g. numeric IDs) before using them in conditions - though this does not fully protect string conditions. - Do not pass user-controlled input to `where()` when using `deleteBatch()`. - For user-controlled conditions, use a normal `delete()` with Query Builder binds instead of `deleteBatch(`). - Where possible, express required matching values through the batch data and `onConstraint()` rather than as separate user-controlled `where()` clauses.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.3.0 Fixed in: 4.7.4 composer require codeigniter4/framework:^4.7.4 References
- https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-63221 [ADVISORY]
- https://github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559f [WEB]
- https://github.com/codeigniter4/CodeIgniter4 [PACKAGE]
- https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4 [WEB]