CVE-2026-63222
HIGHCodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
Title source: cnaDescription
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-hhmc-q9hp-r662
X_Refsource_Misc x_refsource_misc
https://github.com/codeigniter4/CodeIgniter4/commit/20ebcf4694d96d3c97fbc3938e360730e4f54618
X_Refsource_Misc x_refsource_misc
https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4
Scores
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (1)
codeigniter4/CodeIgniter4
< 4.7.4
Published
Jul 31, 2026
Tracked Since
Jul 31, 2026