THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hhmc-q9hp-r662 (high) — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

[GHSA] GHSA-hhmc-q9hp-r662 (high) — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

medgithub_advisoriesPublished 2026-08-07

GHSA-hhmc-q9hp-r662 Severity: high CVE: CVE-2026-63222

CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

### Impact In affected versions, calling `UploadedFile::move()` **without a second argument** uses the client-provided filename without sanitization. Depending on the destination path and server configuration, an attacker can supply a filename containing

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hhmc-q9hp-r662