Feed/CVE-2026-63222
CVE-2026-63222HIGHCVSS 7.5

CVE-2026-63222

Published Jul 31, 2026·Updated Aug 7, 2026

NVD Description

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

Affected Packages (1)

codeigniter4/frameworkCOMPOSER
Fixed in 4.7.4

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free