A critical security vulnerability has been discovered in the CodeIgniter4 PHP framework, allowing attackers to bypass file upload validation and potentially achieve remote code execution (RCE) on affected web applications.
Tracked as CVE-2026-48062 and published via GitHub Security Advisory GHSA-2gr4-ppc7-7mhx, the flaw carries a maximum-severity CVSS v3.1 score, reflecting its network-exploitable, zero-interaction nature.
The root cause lies in how CodeIgniter4’s ext_in validation rule evaluates uploaded files. Instead of checking the client-provided filename extension, the rule was incorrectly checking the MIME-derived guessed extension, a subtle but dangerous distinction.
Critical CodeIgniter File Upload Vulnerability
In practice, this means an attacker can craft a file named shell.php that contains GIF-like binary content. When submitted through an upload form, the framework detects the MIME type as image/gif and maps the guessed extension to gif. A validation rule such as:
uploaded[avatar]|is_image[avatar]|mime_in[avatar,image/gif]|ext_in[avatar,gif]
would pass without error even though the actual filename carries a .php extension. The mismatch between what the server thinks it received and what it actually stored is the heart of the exploit.
The weakness is classified under CWE-434: Unrestricted Upload of File with Dangerous Type, a well-known vulnerability class that consistently appears in OWASP’s top web application risks.
Not every CodeIgniter4 deployment is vulnerable. Exploitation requires a specific combination of conditions to be present simultaneously. The application must accept user-controlled file uploads and rely on ext_in as its primary extension validation mechanism.
Beyond that, it must save uploaded files using the original client-provided filename via $file->move($path), store those files in a web-accessible directory, and permit PHP or other server-side executable scripts to run from that location.
When all five conditions align, a remote, unauthenticated attacker can upload a weaponized PHP webshell disguised as an image and then access it directly via the browser to execute arbitrary commands on the underlying server.
All CodeIgniter4 framework versions prior to 4.7.2 are affected. The vulnerability was patched in version 4.7.3, released by maintainer Paulbalandan. Developers should upgrade to v4.7.3 or later immediately to eliminate the risk entirely.
For teams unable to patch immediately, several interim measures significantly reduce exposure. The most effective approach is to store uploaded files outside the public web root, for example, under writable/uploads so that even a successfully uploaded webshell cannot be accessed via a browser.
Developers should also replace $file->move($path) with $file->store() or $file->move($path, $file->getRandomName()) to strip attacker-controlled filenames from the equation entirely.
Additionally, disabling PHP script execution in any public upload directory through server-level configuration adds a strong defensive layer.
As a final safeguard, manually verifying that $file->getClientExtension() matches an allowlist and aligns with $file->guessExtension() before moving any file, close the validation gap directly.
The vulnerability was responsibly reported by security researcher z3moo, with additional contribution from teebow1e.
Organizations relying on CodeIgniter4 for file upload functionality should treat this as a priority patch, given the zero-privilege, network-accessible attack surface and the direct path to remote code execution it exposes.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.