THREAT OPS › Threat News › [GHSA] GHSA-hhmc-q9hp-r662 (high) — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
[GHSA] GHSA-hhmc-q9hp-r662 (high) — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
GHSA-hhmc-q9hp-r662 Severity: high CVE: CVE-2026-63222
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
### Impact In affected versions, calling `UploadedFile::move()` **without a second argument** uses the client-provided filename without sanitization. Depending on the destination path and server configuration, an attacker can supply a filename containing
Indicators of compromise
- CVE-2026-63222cve
Original source: https://github.com/advisories/GHSA-hhmc-q9hp-r662