CVE-2026-63223 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-63223 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-63223 is a critical unsafe file upload validation flaw in composer codeigniter4/framework that can lead to remote code execution in common vulnerable setups. The issue becomes dangerous when apps trust upload checks like is_image or mime_in without independently validating the file extension, then save the upload using the attacker-controlled filename in a web-accessible directory.

Patch immediately to v4.7.4 or later. This is not currently listed as exploited in the wild, but the attack path is straightforward enough that solo developers and small teams should treat it as urgent.

Immediate Action

  • Upgrade CodeIgniter4/framework to v4.7.4+ as soon as possible. See the vendor advisory: vendor advisory.
  • Stop preserving client filenames for uploads. Use a random name or store the file outside the public web root.
  • Move uploads out of web-accessible paths where possible, ideally to writable/uploads or another non-public directory.
  • Disable PHP/script execution in any directory that must remain publicly reachable.
  • Rollback guidance: if patching breaks upload handling, roll back only the app release, not the security fix; keep the framework upgrade and adjust upload code instead.
  • Isolate the service temporarily if you cannot patch today: restrict upload endpoints, add auth, or place the app behind maintenance mode until fixed.

Affected Versions

  • composer codeigniter4/framework@<4.7.4 vulnerable; upgrade to 4.7.4+.
  • Any application using vulnerable upload logic with is_image or mime_in without an independent extension check is at risk.
  • Apps that save uploads with the original client filename into a web root are especially exposed.
  • Safe target: composer codeigniter4/framework@4.7.4 or later.

Resolution Guide

Update the dependency first. Then harden upload handling so the fix does not depend on a single validation check.

# Composer
composer require codeigniter4/framework:^4.7.4

# If you use a lockfile and want a clean refresh
composer update codeigniter4/framework --with-all-dependencies
# npm / yarn / pnpm are not typically used for this PHP package,
# but if your app has a JS upload proxy or companion service, update it separately.
npm audit
yarn audit
pnpm audit
# Python / pip / pipx
# Not directly applicable to CodeIgniter4, but useful if you run a sidecar upload scanner.
pip install --upgrade <your-upload-scanner-package>
pipx upgrade <tool-name>
# Java / Maven / Gradle
# Not directly applicable to this PHP framework package.
# If your stack includes a gateway or scanner, update that component here.
mvn versions:use-latest-releases
./gradlew dependencies
# Linux package managers
apt list --upgradable
sudo apt upgrade
yum check-update
sudo yum update
# Docker
# Rebuild with the patched application image tag.
docker pull <your-image>:TODO_PATCHED_TAG
docker compose up -d --build

Config hardening:

# Store uploads outside public web root
$path = WRITEPATH . 'uploads';

# Use a random filename instead of the client name
$file->move($path, $file->getRandomName());

# Prefer store() when suitable
$file->store();

Minimal code fix example:

$file = $this->request->getFile('upload');

if (! $file->isValid()) {
    throw new \RuntimeException('Upload failed');
}

$allowed = ['jpg', 'jpeg', 'png', 'gif'];
$clientExt = strtolower($file->getClientExtension());

if (! in_array($clientExt, $allowed, true)) {
    throw new \RuntimeException('Invalid file extension');
}

if (! $file->is_image || ! in_array(strtolower($file->guessExtension()), $allowed, true)) {
    throw new \RuntimeException('Invalid image upload');
}

$file->move(WRITEPATH . 'uploads', $file->getRandomName());

Web server hardening: block script execution in upload directories.

# Apache example
<Directory "/var/www/html/uploads">
    php_admin_flag engine off
    <FilesMatch "\.php$">
        Require all denied
    </FilesMatch>
</Directory>

# Nginx example
location ^~ /uploads/ {
    location ~ \.php$ { deny all; }
}

Detection & Verification

Check your installed version:

composer show codeigniter4/framework
composer outdated codeigniter4/framework

Search for risky upload patterns:

grep -RInE "is_image|mime_in|getClientName|move\(|store\(" app/ writable/ .

Look for dangerous combinations: validation using is_image or mime_in, then saving with the original filename, then placing files in a public directory.

Verify the fix:

composer show codeigniter4/framework | grep versions
php -r 'echo \CodeIgniter\CodeIgniter::CI_VERSION, PHP_EOL;'

Functional test: upload a harmless file with a misleading extension and confirm it is rejected or renamed, and that the final stored file is not executable from the web.

Risk and Impact

If exploited, an attacker may upload a file that the application accepts as safe but the server later treats as executable code. In the worst case, this can lead to remote code execution, full application compromise, data theft, and lateral movement into adjacent services.

The blast radius is highest for small teams that host uploads under the web root, rely on filename preservation, or have limited server hardening. Even without confirmed in-the-wild exploitation, the combination of critical severity and common misconfiguration makes this a high-priority patch.

Keep reading