Summary
CVE-2026-63222 is a high-severity path traversal vulnerability in CodeIgniter4, a widely-used PHP full-stack web framework. The flaw resides in the UploadedFile::move() method, which — when invoked without a second argument — passes the client-supplied filename directly to the filesystem without sanitization, allowing a remote unauthenticated attacker to write uploaded content to arbitrary locations on the server. With a CVSS v3.1 base score of 7.5 (High), the vulnerability is exploitable over the network with no authentication or user interaction required, and can result in remote code execution (RCE) if a malicious file is written to a web-accessible directory.
Technical details
- Root cause:
UploadedFile::move()uses the client-provided filename as the default destination filename when its optional second argument is omitted, without stripping or blocking path traversal sequences (e.g.,../../public/shell.php). - Trigger condition: Any application code that calls
$file->move($targetDir)without explicitly supplying a sanitized filename as the second argument is vulnerable. This is a common and documented usage pattern in CodeIgniter4 applications. - Attack vector: A remote, unauthenticated attacker submits a crafted multipart file upload request with a filename containing path traversal sequences. No authentication, privilege escalation, or user interaction is needed.
- Impact: Arbitrary file write outside the intended upload directory. If the attacker writes a PHP file (e.g., a web shell) to a publicly accessible path, full remote code execution on the server is achievable. The CVSS integrity impact is rated High; confidentiality and availability are not directly impacted by the file-write primitive itself.
- Post-fix behavior: As of v4.7.4,
UploadedFile::move()sanitizes the client-provided filename when no second argument is supplied. When a caller explicitly passes a filename as the second argument, sanitization remains the caller’s responsibility.
Affected software
- CodeIgniter4 — all versions prior to 4.7.4
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Mitigation and recommended actions
- Immediate — upgrade: Update CodeIgniter4 to version 4.7.4 or later, which contains the vendor-supplied fix sanitizing client-provided filenames in
UploadedFile::move(). - If immediate patching is not possible:
- Audit all application upload handlers and ensure
UploadedFile::move()is always called with an explicitly sanitized filename supplied as the second argument (do not rely on the client-provided name). - Ensure upload destination directories are not web-accessible and that the web server is configured to deny execution of uploaded content (e.g., deny PHP execution in upload folders via server configuration).
- Apply network-level controls to restrict file upload endpoints to trusted sources where feasible.
- Audit all application upload handlers and ensure
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

