GHSA-mmj4-63m4-r6h5

Suggest an improvement
Source
https://github.com/advisories/GHSA-mmj4-63m4-r6h5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mmj4-63m4-r6h5/GHSA-mmj4-63m4-r6h5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mmj4-63m4-r6h5
Aliases
Published
2026-08-07T18:24:21Z
Modified
2026-08-07T18:31:29Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Details

Impact

This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they:

  • validate uploads using is_image or mime_in without an independent safe extension check, such as ext_in on patched versions
  • save uploaded files using the client-supplied filename
  • place uploads in a web-accessible directory where PHP files can execute

Patches

Upgrade to v4.7.4 or later.

Workarounds

  • Save uploads outside the public web root, preferably under writable/uploads.
  • Use $file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.
  • Disable script execution in any public upload directory.
  • Manually verify the client filename extension before moving the file.
  • For image uploads, reject files when $file->getClientExtension() is not an allowed image extension.
  • For exact MIME-type validation, reject files when $file->getClientExtension() does not match $file->guessExtension().
Database specific
{
    "cwe_ids":  [
        "CWE-434"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-07T18:24:21Z",
    "nvd_published_at":  "2026-07-31T06:16:32Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Packagist / codeigniter4/framework

Package

Name
codeigniter4/framework
Purl
pkg:composer/codeigniter4/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.4

Affected versions

v4.*
v4.0.0-alpha.3
v4.0.0-alpha.4
v4.0.0-alpha.5
v4.0.0-beta.1
v4.0.0-beta.2
v4.0.0-beta.3
v4.0.0-beta.4
v4.0.0-rc.1
v4.0.0-rc.2
v4.0.0-rc.2.1
v4.0.0-rc.3
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.2.7
v4.2.8
v4.2.9
v4.2.10
v4.2.11
v4.2.12
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
v4.3.8
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.4.6
v4.4.7
v4.4.8
v4.5.0
v4.5.1
v4.5.2
v4.5.3
v4.5.4
v4.5.5
v4.5.6
v4.5.7
v4.5.8
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.7.0
v4.7.1
v4.7.2
v4.7.3
4.*
4.0.0-rc.4
4.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mmj4-63m4-r6h5/GHSA-mmj4-63m4-r6h5.json"