CodeIgniter4 fixed a high-severity file upload validation flaw tracked as CVE-2026-63223 that could let remote attackers upload executable files when applications rely on the is_image or mime_in rules without separately enforcing a safe filename extension. The issue affects versions earlier than 4.7.4 and stems from validation logic that accepted files based on content-derived MIME type while failing to independently block dangerous client-supplied extensions such as .php.
The vulnerability becomes exploitable when an application preserves the original filename, stores uploads in a web-accessible and script-enabled directory, and trusts those validation rules alone. CodeIgniter4 version 4.7.4 hardens both checks by requiring safe, non-empty extensions for is_image and rejecting extension-versus-content mismatches for mime_in, while still permitting extensionless uploads such as browser-generated Blob files; the project also added tests covering mismatched extensions, non-image content, SVG handling, and extensionless filenames.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CodeIgniter4 commit for version 4.7.4 updated the `is_image` and `mime_in` validation rules to also verify client filename extensions, preventing dangerous files such as `.php` from passing as images under certain conditions. The patch also added tests covering mismatched extensions, non-image content, SVG handling, and extensionless filenames.
CVE-2026-63223 was published as a vulnerability affecting CodeIgniter4 versions earlier than 4.7.4, describing an uploaded file extension validation bypass in the `is_image` and `mime_in` rules. The disclosure states exploitation could allow remote attackers to upload executable content when applications preserve client filenames and store uploads in web-accessible script-enabled directories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.