GHSA-mmj4-63m4-r6h5CriticalCVSS 9.8

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they:

  • validate uploads using is_image or mime_in without an independent safe extension check, such as ext_in on patched versions
  • save uploaded files using the client-supplied filename
  • place uploads in a web-accessible directory where PHP files can execute

Patches

Upgrade to v4.7.4 or later.

Workarounds

  • Save uploads outside the public web root, preferably under writable/uploads.
  • Use $file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.
  • Disable script execution in any public upload directory.
  • Manually verify the client filename extension before moving the file.
  • For image uploads, reject files when $file->getClientExtension() is not an allowed image extension.
  • For exact MIME-type validation, reject files when $file->getClientExtension() does not match $file->guessExtension().

🎯 Affected products1

  • composer/codeigniter4/framework:< 4.7.4

🔗 References (5)